Third-Party Service Notice
Last Updated: 2026-06-05
This document provides a detailed description of the third-party services used by Xuzhou Mangxu Software Technology Co., Ltd. (hereinafter referred to as "Mangxu Software" or "we") in the course of providing services, as well as data sharing practices. In accordance with Article 23 (entrusted processing) and Article 21 (provision to third parties) of the Personal Information Protection Law of the People's Republic of China (PIPL), Article 30 of the Data Security Law (DSL), Article 7 of the Interim Measures for the Management of Generative Artificial Intelligence Services, and other applicable laws and regulations, we fully disclose to you the third-party data processing activities and safeguard your right to know and right to choose.
I. List of Third-Party Services and Data Processing Details
The table below lists all third-party service providers we currently use, as well as the types of data shared with each provider in the course of service provision, the purposes, retention periods, and security measures. We have entered into Data Processing Agreements (DPAs) with all third-party service providers and conduct regular assessments and audits of their data security capabilities.
| Service Type | Service Provider | Service Purpose | Shared Data Scope | Data Storage Location | Retention Period | Legal Basis |
|---|---|---|---|---|---|---|
| AI Inference Engine (LLM) | (To be completed with actual provider) | Intelligent conversation, content generation, AI analysis | AI conversation content, business data sent by users to the LLM for processing (excluding identity information) | Mainland China | Conversation content: 180 days; LLM-processed data: deleted immediately after processing (not retained) | Article 13 of PIPL (consent) + Article 7 of the Interim Measures for the Management of Generative AI Services |
| Cloud Computing Services (server hosting) | (To be completed with actual provider) | Server hosting, data storage | All business data (encrypted in transmission and at rest) | Mainland China | Retained by data category (see individual feature descriptions) | Article 21 of PIPL (entrusted processing) + Article 30 of DSL |
| Object Storage (documents/files/images/videos) | (To be completed with actual provider) | Storage of files, images, videos; knowledge base document storage | Documents, images, and videos uploaded by users (including knowledge base content) | Mainland China | Permanent (users may delete on their own); vectorized embeddings synchronized with source documents | Article 13 of PIPL (contract performance) + Data Security Law |
| Email Service | (To be completed with actual provider) | System notifications, marketing emails | Email addresses, email content (including authentication emails and notification emails) | Mainland China | Email notification records: 180 days | Article 13 of PIPL (contract performance) |
| SMS Service | (To be completed with actual provider) | Verification codes, notification text messages | Mobile phone numbers | Mainland China | SMS notification records: 180 days | Article 13 of PIPL (contract performance) |
| Payment Service | (To be completed with actual provider) | Online payment processing | Order amounts (excluding complete payment information) | Mainland China | Retained in accordance with payment industry regulatory requirements (no less than 5 years) | E-commerce Law + Accounting Law |
| Data Analytics (visitor behavior statistics) | (To be completed with actual provider) | Website traffic statistics, user behavior analysis | De-identified behavioral data (IP addresses, browsing history, device information) | Mainland China | 2 years | Article 13 of PIPL (consent) |
| CDN Acceleration | (To be completed with actual provider) | Content distribution and acceleration | Static resources, IP addresses | Mainland China | During cache period (not exceeding 30 days) | Cybersecurity Law (ensuring system stability) |
Special Note: AI content generation records (including AI-assisted creative content and version history) are retained permanently due to the ongoing need for model optimization and algorithm filing audits; however, users may contact customer service to request deletion of their generated personal creative records. In addition, user authentication and login credentials (such as password hashes and tokens) are managed through third-party identity authentication services and retained for the duration of the account's existence, to comply with real-name system requirements (Article 21 of the Cybersecurity Law).
II. Data Sharing Principles
- Principle of Minimal Necessity: Only the minimum data necessary to realize the service functions is shared, and the data scope is reviewed on a regular basis
- Purpose Limitation: Third parties may not use shared data for purposes other than those agreed upon, as explicitly constrained in the DPA
- Security Safeguards: All third parties have signed Data Processing Agreements (DPAs) and commit to adopting security measures that meet national standards, including encryption, access control, and audit logs
- No Cross-Border Data Transfer: All third-party services are deployed within Mainland China, and no data is transferred across borders (pursuant to Article 38 of PIPL)
- Regular Assessment: At least once a year, we assess and audit the data security capabilities of third parties and retain the assessment reports
- Separate Consent: For scenarios involving the sharing of sensitive personal information (such as identity information), we will obtain your separate consent
III. Third-Party SDK Usage
Our mobile or web platforms may integrate the following third-party SDKs:
- Analytics SDK: Collects device information, page navigation paths, and click behavior for product improvement and user profile analysis (based on your consent, can be disabled at any time)
- Push Notification SDK: Used to send you message notifications (e.g., order notifications, system alerts); collects device identifiers (e.g., IMEI, OAID)
- Identity Authentication SDK: Used for quick login and identity verification; shares device information and credential data
For the detailed privacy policy link and data processing description for each SDK, you may request them via privacy@mangxu.com or view the "SDK List" settings page in the application.
IV. Protection of Minors' Information
Our services are not intended for minors under the age of 14. If you are a minor between the ages of 14 and 18, please use this service under the supervision of a legal guardian. If you discover that we have inadvertently collected a minor's personal information, please contact us immediately, and we will delete it as soon as possible.
V. Your Choices and Rights
- Right to Know: You have the right to know the details of the third parties with whom we share data, including the service provider names, data types, purposes, etc. (disclosed in this document; please contact us for more detailed information)
- Right to Withdraw Consent: For third-party sharing that relies on separate consent (such as AI conversation analysis and personalized recommendations), you may disable the relevant function at any time in the system settings. Withdrawing consent does not affect the lawfulness of processing conducted prior to the withdrawal
- Opt-Out of Direct Marketing: You may choose not to use features that rely on third-party services (e.g., disabling the AI assistant or personalized recommendations). You may also disable third-party analytics cookies in your cookie settings
- Right to Deletion: You may contact us to request the deletion of your personal information that we have shared with third parties (except where retention is required by law), and the third parties will delete such information accordingly
- Complaints and Reporting: If you believe that our third-party data processing violates applicable laws and regulations, you may file a complaint with the cyberspace administration authorities or public security authorities
VI. Disclaimer Regarding Third-Party Links
This website may contain links to third-party websites. These websites have their own privacy policies and terms of service, and we assume no responsibility for the content or practices of third-party websites. We recommend that you carefully read their privacy policies before use.
VII. Emergency Response to Data Security Incidents
In the event of a data security incident involving a third-party service provider (e.g., a data breach), we will immediately activate our emergency response plan, notify affected users, and report to the regulatory authorities. We will require the third party to notify us immediately upon the occurrence of an incident and to cooperate with the investigation and determination of liability.
VIII. Updates and Notifications to This Notice
As our business evolves, we may update this Third-Party Service Notice. Material changes (such as the addition of significant new third parties or substantive changes to the types of data shared) will be notified to you via in-app messages, email, or pop-up notifications prior to their effective date, and we will obtain your separate consent where necessary (if applicable).