Data export

Cross-Border Data Transfer Statement

Learn about Xuzhou Mangxu Software Technology Co., Ltd.'s cross-border data transfer policy: Currently, all data is processed within China and not transferred overseas; in the future, if cross-border transfer is required, we will strictly comply with legal requirements such as security assessments and standard contracts, and ensure your right to know.

Version v1Effective Date2026/05/13Last Updated2026/08/09

Data Export Notice

Last Updated: 2026-06-05

This document provides details on the policies and measures of Xuzhou Mangxu Software Technology Co., Ltd. regarding cross-border data transfers, in accordance with Chapter 3, Section 3 (Articles 38 through 43) of the Personal Information Protection Law of the People's Republic of China, the Security Assessment Measures for Data Export (effective September 1, 2022), and the Measures for Standard Contracts for the Export of Personal Information (effective June 1, 2023).

1. Current Status of Data Export

Important Notice: At present, all data processing activities of Xuzhou Mangxu Software Technology Co., Ltd. are performed within the territory of the People's Republic of China. We do not transfer your personal information outside of China.

  • All servers are deployed in data centers located within mainland China.
  • AI inference services use models deployed domestically.
  • All third-party services are selected from domestic service providers.
  • Employee remote access is restricted to domestic networks.

2. Compliance Framework for Data Export

Should future business needs require providing personal information abroad, we will strictly adhere to the following legal requirements:

2.1 Security Assessment (PIPL Article 40)

If any of the following conditions is met, a security assessment organized by the national cybersecurity and informatization department must be passed:

  • Operators of critical information infrastructure provide personal information abroad.
  • Processors that handle personal information of more than 1 million people.
  • An entity that has cumulatively provided personal information of 100,000 people abroad since January 1 of the previous year.
  • An entity that has cumulatively provided sensitive personal information of 10,000 people abroad since January 1 of the previous year.

2.2 Standard Contract (PIPL Article 38, Item 3)

For data exports that do not require a security assessment, we will enter into an agreement with the overseas recipient using the standard contract formulated by the national cybersecurity and informatization department. The contract will include:

  • The scope, purpose, and method of the data being exported.
  • The overseas recipient's obligations for data security protection.
  • A mechanism for safeguarding the rights of data subjects.
  • Dispute resolution and regulatory cooperation.

2.3 Personal Information Protection Certification

Obtaining personal information protection certification from a professional institution recognized by the national cybersecurity and informatization department is also an available pathway for compliant data export.

3. Your Right to Be Informed

In accordance with PIPL Article 39, if data export occurs in the future, we will inform you before the transfer:

  • The name of the overseas recipient (whether an organization or individual).
  • Contact information.
  • The purpose and method of processing.
  • The types of personal information involved.
  • The methods and procedures for exercising your rights with the overseas recipient.

We will also obtain your separate consent.

4. Data Localization Commitment

We commit to the following:

  • Prioritizing domestic service providers and data centers.
  • Regularly reviewing our supply chain to ensure that data is not indirectly transferred abroad.
  • Providing at least 30 days' prior notice and re-obtaining consent before any change to data storage locations.
  • Storing important data and core data strictly within China, with no cross-border transfer of such data.