Compliance Overview

Compliance Overview

Mangxu Software strictly complies with the Personal Information Protection Law, providing you with transparent policies on the collection, use, and protection of personal information, and safeguarding your data subject rights.

Version v1Effective Date2026/05/13Last Updated2026/08/09

Legal Compliance Overview

Last Updated: 2026-06-05

Xuzhou Mangxu Software Technology Co., Ltd. (hereinafter referred to as "Mangxu Software"), as an enterprise-grade AI intelligent operations platform, deeply recognizes the importance of data compliance and legal norms. We have established a compliance management system covering the entire business chain, ensuring that platform operations comply with Chinese laws and regulations, and continuously optimizing compliance measures based on actual data processing activities.

I. Applicable Laws and Regulations System

Regulation NameEffective DateApplicable AreaCorresponding Measures on This Platform
Personal Information Protection Law (PIPL)2021.11.01Full lifecycle of personal information processingPrivacy policy, data subject rights, consent management; specifically based on PIPL Article 13 (legal basis), Article 17 (notification obligations), Article 23 (separate consent for third-party sharing), etc.
Data Security Law2021.09.01Data classification and grading and security protectionData grading management, security assessment, emergency response; directory-based protection for important data (e.g., knowledge base content)
Cybersecurity Law2017.06.01Network operation security and information securityClassified protection, log retention (no less than 6 months), security incident reporting; real-name authentication requirements
Provisions on the Administration of Algorithmic Recommendations in Internet Information Services2022.03.01Algorithmic recommendation service managementAlgorithm filing, recommendation transparency, user choice (ability to disable personalized recommendations)
Interim Measures for the Administration of Generative Artificial Intelligence Services2023.08.15Generative AI service managementAI content labeling, usage statement, security assessment; dialogue data retention not exceeding 180 days
Provisions on the Protection of Children's Personal Information Online2019.10.01Protection of information of children under 14 years oldChildren's privacy protection policy, age verification mechanism
Measures for Security Assessment of Data Outbound Transfers2022.09.01Cross-border data transfer managementLocalized data storage, security assessment before outbound transfer
E-Commerce Law2019.01.01E-commerce activity regulationConsumer rights protection, electronic contract management, order data retention for 10 years (Accounting Law requirement)
Anti-Unfair Competition Law2019.04.23Market competition conduct regulationLegally collect public information for market analysis, does not involve trade secrets
Advertising Law2018.11.29Advertising content and publicationEnsure authenticity of content performance data, avoid false advertising
AI Safety Governance FrameworkReference standardAI system security and auditabilityAI orchestration decision logs retained for 2 years, ensuring explainability and audit trail

II. Compliance Management Architecture

2.1 Organizational Structure

  • Data Protection Officer (DPO): oversees data compliance management
  • Legal Compliance Department: responsible for regulatory tracking, risk assessment, and compliance audit
  • Information Security Department: responsible for technical security implementation and security incident response
  • Compliance contact persons for each business module: responsible for compliance implementation in their respective modules

2.2 Compliance Coverage of Nine Business Modules

This platform includes 9 business modules. Each module implements specific compliance measures based on actual data collection points. The following details the data processing activities, data types, collection methods, retention periods, third-party sharing circumstances, and legal bases:

ModuleData Processing ActivityData TypeCollection MethodRetention PeriodThird-Party SharingCompliance Measures and Legal Basis
Website Management (website)Visitor browsing behavior tracking, Cookie and LocalStorage, contact/inquiry forms, quotation request formsBehavioral data, technical data, personal information (name, contact information)Cookie/tracking scripts, form submissionBrowsing behavior 2 years, Cookie 1 year, form data 3 yearsNo (not shared with third parties)Cookie consent management (PIPL Article 13 consent); visitor data anonymization; form data used for business communication (PIPL Article 13 contract performance)
Intelligent Content (cortex)AI content generation records, content publishing and distribution dataBusiness data (generated content, distribution volume)AI invocation, tracking analysisGeneration records permanent (user-deletable), distribution data 3 yearsYes (AI content generation records shared with LLM service provider)AI content labeling, manual review; separate consent required for third-party sharing (PIPL Article 23); compliant with the Interim Measures for the Administration of Generative AI
AI Engine (ai)AI dialogue content, content sent to LLM for processing, model usage statisticsPersonal information (dialogue content), business data (sent text), technical data (usage)API callsDialogue content 180 days, deleted immediately after LLM processing, usage statistics 1 yearYes (dialogue content and sent content shared with LLM provider)Based on user consent (PIPL Article 13); Data Security Law requires important data not to leave the country; usage statistics for monitoring and billing (legitimate interests)
Knowledge Base (kb)Document upload and knowledge base content, document vectorization embeddingBusiness data (documents, vectors)User upload, AI vectorizationPermanent (user-deletable), vectors synchronized with source documentsYes (vectorized embeddings may be shared with third-party AI infrastructure)Access control, data encryption; agreements required for third-party sharing (Data Security Law); compliance based on PIPL Article 13 contract performance
Audience Hub (nexus)Member registration information, user profiling and behavioral tags, user journey trackingPersonal information (name, mobile phone, etc.), behavioral tags, journey dataForms, AI analysis, trackingRegistration information account duration + 3 years, behavioral tags 2 years, journey tracking 2 yearsNo (not shared with third parties)Explicit consent (PIPL Article 13); users can disable personalized recommendations (Algorithmic Recommendation Provisions); de-identification of profile data
Enterprise Office (office)Business opportunity contact information, order and contract data, channel partner informationPersonal information (contacts), financial data (amounts), business data (cooperation information)Form entry, CRM systemBusiness opportunities 5 years, orders 10 years (Accounting Law requirement), channel cooperation period + 3 yearsNo (not shared with third parties)Principle of minimal necessity; order data retained per Accounting Law; channel data for contract performance (PIPL Article 13)
Beacon Optimization (beacon)Competitor public data monitoring, algorithmic recommendation and personalization rules, user behavioral data sampling analysisBusiness data (public information), algorithmic rules, behavioral data (desensitized)API collection, AI learning, trackingPublic data 1 year, rules duration, behavior sampling 1 yearNo (not shared with third parties)Only legally collect public information (Anti-Unfair Competition Law); algorithm filing (Algorithmic Recommendation Provisions); behavioral data desensitized before analysis (PIPL Article 13 legitimate interests)
Operations Command (orchestrator)AI orchestration decision logsTechnical data (decision records)API logs2 yearsNo (not shared with third parties)Auditability requirements (AI Safety Governance Framework); logs used for troubleshooting and compliance audit
System Management (system)User authentication and login credentials, email/SMS notification recordsPersonal information (account, password, mobile phone number), operation logsForms, API callsAccount duration, notification records 180 daysYes (authentication credentials shared with identity verification service provider; notification records shared with SMS/email service providers)Real-name registration (Cybersecurity Law); third-party sharing requires data processing agreements and user consent (PIPL Article 23)

III. Compliance Policy System

  • Privacy Impact Assessment (PIA): conduct a privacy impact assessment before launching new features, focusing on personal data processing scenarios
  • Data Protection Impact Assessment (DPIA): conduct a special assessment before high-risk processing activities (e.g., AI dialogue, user profiling)
  • Data Retention and Destruction Strategy: establish automatic cleanup mechanisms based on actual retention periods of each module (180 days to permanent), anonymize or securely delete expired data
  • Third-Party Sharing Management: for modules with third-party sharing (Intelligent Content, AI Engine, Knowledge Base, System Management), sign data processing agreements, ensure third parties meet the same security standards, and obtain users' separate consent
  • Regular Compliance Audit: conduct internal compliance audits every six months, covering actual data processing activities of all business modules
  • Employee Training: annual data security and privacy training for all employees, with emphasis on AI data processing standards
  • Supplier Management: data security assessment and agreements for third-party service providers, requiring them to comply with PIPL, Data Security Law, etc.
  • Incident Response: emergency response plans for security incidents such as data breaches, initiate investigation within 24 hours and notify regulators

This compliance center provides the following legal documents, constituting a complete compliance disclosure system. Each document is written based on actual data collection points:

  • Privacy Policy — Comprehensive description of personal information processing (covering personal data collection points of all modules)
  • Terms of Service — Service usage agreement
  • Cookie Policy — Management of Cookie and similar technologies
  • Data Security Statement — Security measures and incident response
  • AI Usage Statement — AI technology transparency disclosure (dialogue data, content generation, etc.)
  • Data Subject Rights — User rights exercise guide
  • Intellectual Property Statement — Copyright and trademark protection
  • Third-Party Services Statement — Data sharing recipients, purposes, and safeguards
  • Children's Privacy Protection — Protection of minors' information
  • Data Outbound Transfer Statement — Cross-border transfer compliance (if any)

V. Compliance Officer

Data Protection Officer (DPO):
Contact email: www@mangxu.net
Contact phone: 0516-87722111 (recommended to fill in)
Office address: Room 818, Building 2, Sanbao Plaza, Quanshan District, Xuzhou, Jiangsu Province

For compliance complaints and suggestions, please send to: xilu@139.com

If you have any questions about data processing or wish to exercise your data subject rights, please contact us through the above channels, and we will respond as soon as possible.