Legal Compliance Overview
Last Updated: 2026-06-05
Xuzhou Mangxu Software Technology Co., Ltd. (hereinafter referred to as "Mangxu Software"), as an enterprise-grade AI intelligent operations platform, deeply recognizes the importance of data compliance and legal norms. We have established a compliance management system covering the entire business chain, ensuring that platform operations comply with Chinese laws and regulations, and continuously optimizing compliance measures based on actual data processing activities.
I. Applicable Laws and Regulations System
| Regulation Name | Effective Date | Applicable Area | Corresponding Measures on This Platform |
|---|---|---|---|
| Personal Information Protection Law (PIPL) | 2021.11.01 | Full lifecycle of personal information processing | Privacy policy, data subject rights, consent management; specifically based on PIPL Article 13 (legal basis), Article 17 (notification obligations), Article 23 (separate consent for third-party sharing), etc. |
| Data Security Law | 2021.09.01 | Data classification and grading and security protection | Data grading management, security assessment, emergency response; directory-based protection for important data (e.g., knowledge base content) |
| Cybersecurity Law | 2017.06.01 | Network operation security and information security | Classified protection, log retention (no less than 6 months), security incident reporting; real-name authentication requirements |
| Provisions on the Administration of Algorithmic Recommendations in Internet Information Services | 2022.03.01 | Algorithmic recommendation service management | Algorithm filing, recommendation transparency, user choice (ability to disable personalized recommendations) |
| Interim Measures for the Administration of Generative Artificial Intelligence Services | 2023.08.15 | Generative AI service management | AI content labeling, usage statement, security assessment; dialogue data retention not exceeding 180 days |
| Provisions on the Protection of Children's Personal Information Online | 2019.10.01 | Protection of information of children under 14 years old | Children's privacy protection policy, age verification mechanism |
| Measures for Security Assessment of Data Outbound Transfers | 2022.09.01 | Cross-border data transfer management | Localized data storage, security assessment before outbound transfer |
| E-Commerce Law | 2019.01.01 | E-commerce activity regulation | Consumer rights protection, electronic contract management, order data retention for 10 years (Accounting Law requirement) |
| Anti-Unfair Competition Law | 2019.04.23 | Market competition conduct regulation | Legally collect public information for market analysis, does not involve trade secrets |
| Advertising Law | 2018.11.29 | Advertising content and publication | Ensure authenticity of content performance data, avoid false advertising |
| AI Safety Governance Framework | Reference standard | AI system security and auditability | AI orchestration decision logs retained for 2 years, ensuring explainability and audit trail |
II. Compliance Management Architecture
2.1 Organizational Structure
- Data Protection Officer (DPO): oversees data compliance management
- Legal Compliance Department: responsible for regulatory tracking, risk assessment, and compliance audit
- Information Security Department: responsible for technical security implementation and security incident response
- Compliance contact persons for each business module: responsible for compliance implementation in their respective modules
2.2 Compliance Coverage of Nine Business Modules
This platform includes 9 business modules. Each module implements specific compliance measures based on actual data collection points. The following details the data processing activities, data types, collection methods, retention periods, third-party sharing circumstances, and legal bases:
| Module | Data Processing Activity | Data Type | Collection Method | Retention Period | Third-Party Sharing | Compliance Measures and Legal Basis |
|---|---|---|---|---|---|---|
| Website Management (website) | Visitor browsing behavior tracking, Cookie and LocalStorage, contact/inquiry forms, quotation request forms | Behavioral data, technical data, personal information (name, contact information) | Cookie/tracking scripts, form submission | Browsing behavior 2 years, Cookie 1 year, form data 3 years | No (not shared with third parties) | Cookie consent management (PIPL Article 13 consent); visitor data anonymization; form data used for business communication (PIPL Article 13 contract performance) |
| Intelligent Content (cortex) | AI content generation records, content publishing and distribution data | Business data (generated content, distribution volume) | AI invocation, tracking analysis | Generation records permanent (user-deletable), distribution data 3 years | Yes (AI content generation records shared with LLM service provider) | AI content labeling, manual review; separate consent required for third-party sharing (PIPL Article 23); compliant with the Interim Measures for the Administration of Generative AI |
| AI Engine (ai) | AI dialogue content, content sent to LLM for processing, model usage statistics | Personal information (dialogue content), business data (sent text), technical data (usage) | API calls | Dialogue content 180 days, deleted immediately after LLM processing, usage statistics 1 year | Yes (dialogue content and sent content shared with LLM provider) | Based on user consent (PIPL Article 13); Data Security Law requires important data not to leave the country; usage statistics for monitoring and billing (legitimate interests) |
| Knowledge Base (kb) | Document upload and knowledge base content, document vectorization embedding | Business data (documents, vectors) | User upload, AI vectorization | Permanent (user-deletable), vectors synchronized with source documents | Yes (vectorized embeddings may be shared with third-party AI infrastructure) | Access control, data encryption; agreements required for third-party sharing (Data Security Law); compliance based on PIPL Article 13 contract performance |
| Audience Hub (nexus) | Member registration information, user profiling and behavioral tags, user journey tracking | Personal information (name, mobile phone, etc.), behavioral tags, journey data | Forms, AI analysis, tracking | Registration information account duration + 3 years, behavioral tags 2 years, journey tracking 2 years | No (not shared with third parties) | Explicit consent (PIPL Article 13); users can disable personalized recommendations (Algorithmic Recommendation Provisions); de-identification of profile data |
| Enterprise Office (office) | Business opportunity contact information, order and contract data, channel partner information | Personal information (contacts), financial data (amounts), business data (cooperation information) | Form entry, CRM system | Business opportunities 5 years, orders 10 years (Accounting Law requirement), channel cooperation period + 3 years | No (not shared with third parties) | Principle of minimal necessity; order data retained per Accounting Law; channel data for contract performance (PIPL Article 13) |
| Beacon Optimization (beacon) | Competitor public data monitoring, algorithmic recommendation and personalization rules, user behavioral data sampling analysis | Business data (public information), algorithmic rules, behavioral data (desensitized) | API collection, AI learning, tracking | Public data 1 year, rules duration, behavior sampling 1 year | No (not shared with third parties) | Only legally collect public information (Anti-Unfair Competition Law); algorithm filing (Algorithmic Recommendation Provisions); behavioral data desensitized before analysis (PIPL Article 13 legitimate interests) |
| Operations Command (orchestrator) | AI orchestration decision logs | Technical data (decision records) | API logs | 2 years | No (not shared with third parties) | Auditability requirements (AI Safety Governance Framework); logs used for troubleshooting and compliance audit |
| System Management (system) | User authentication and login credentials, email/SMS notification records | Personal information (account, password, mobile phone number), operation logs | Forms, API calls | Account duration, notification records 180 days | Yes (authentication credentials shared with identity verification service provider; notification records shared with SMS/email service providers) | Real-name registration (Cybersecurity Law); third-party sharing requires data processing agreements and user consent (PIPL Article 23) |
III. Compliance Policy System
- Privacy Impact Assessment (PIA): conduct a privacy impact assessment before launching new features, focusing on personal data processing scenarios
- Data Protection Impact Assessment (DPIA): conduct a special assessment before high-risk processing activities (e.g., AI dialogue, user profiling)
- Data Retention and Destruction Strategy: establish automatic cleanup mechanisms based on actual retention periods of each module (180 days to permanent), anonymize or securely delete expired data
- Third-Party Sharing Management: for modules with third-party sharing (Intelligent Content, AI Engine, Knowledge Base, System Management), sign data processing agreements, ensure third parties meet the same security standards, and obtain users' separate consent
- Regular Compliance Audit: conduct internal compliance audits every six months, covering actual data processing activities of all business modules
- Employee Training: annual data security and privacy training for all employees, with emphasis on AI data processing standards
- Supplier Management: data security assessment and agreements for third-party service providers, requiring them to comply with PIPL, Data Security Law, etc.
- Incident Response: emergency response plans for security incidents such as data breaches, initiate investigation within 24 hours and notify regulators
IV. Legal Document System
This compliance center provides the following legal documents, constituting a complete compliance disclosure system. Each document is written based on actual data collection points:
- Privacy Policy — Comprehensive description of personal information processing (covering personal data collection points of all modules)
- Terms of Service — Service usage agreement
- Cookie Policy — Management of Cookie and similar technologies
- Data Security Statement — Security measures and incident response
- AI Usage Statement — AI technology transparency disclosure (dialogue data, content generation, etc.)
- Data Subject Rights — User rights exercise guide
- Intellectual Property Statement — Copyright and trademark protection
- Third-Party Services Statement — Data sharing recipients, purposes, and safeguards
- Children's Privacy Protection — Protection of minors' information
- Data Outbound Transfer Statement — Cross-border transfer compliance (if any)
V. Compliance Officer
Data Protection Officer (DPO):
Contact email: www@mangxu.net
Contact phone: 0516-87722111 (recommended to fill in)
Office address: Room 818, Building 2, Sanbao Plaza, Quanshan District, Xuzhou, Jiangsu Province
For compliance complaints and suggestions, please send to: xilu@139.com
If you have any questions about data processing or wish to exercise your data subject rights, please contact us through the above channels, and we will respond as soon as possible.