Legal & Compliance Overview
Last updated:2026-06-05
Xuzhou Mangxu Software Technology Co., Ltd. (hereinafter referred to as "Mangxu Software"), as an enterprise-level AI intelligent operation platform, deeply recognizes the importance of data compliance and legal standardization. We have established a compliance management system covering the entire business chain, ensuring that platform operations comply with Chinese laws and regulations, and continuously optimizing compliance measures based on actual data processing activities.
I. Applicable Legal and Regulatory System
| Regulation Name | Effective Date | Applicable Domain | Corresponding Platform Measures |
|---|---|---|---|
| Personal Information Protection Law (PIPL) | 2021.11.01 | Full lifecycle of personal information processing | Privacy policy, data subject rights, consent management; specifically based on Article 13 of PIPL (legal basis), Article 17 (obligation to inform), Article 23 (separate consent for third-party sharing), etc. |
| Data Security Law | 2021.09.01 | Data classification, grading, and security protection | Data tiered management, security assessments, emergency response; directory-based protection for important data (e.g., knowledge base content) |
| Cybersecurity Law | 2017.06.01 | Network operation security and information security | Classified protection, log retention (not less than 6 months), security incident reporting; real-name authentication requirements |
| Internet Information Service Algorithmic Recommendation Management Provisions | 2022.03.01 | Algorithmic recommendation service management | Algorithm filing, recommendation transparency, user choice (ability to disable personalized recommendations) |
| Interim Measures for the Management of Generative Artificial Intelligence Services | 2023.08.15 | Generative AI service management | AI content labeling, usage declarations, security assessments; dialogue data retention not exceeding 180 days |
| Provisions on the Protection of Children's Personal Information Online | 2019.10.01 | Protection of information of children under 14 | Children's privacy protection policy, age verification mechanism |
| Measures for Security Assessment of Data Export | 2022.09.01 | Cross-border data transfer management | Localized data storage, security assessment required before transfer |
| E-Commerce Law | 2019.01.01 | E-commerce activity regulation | Consumer rights protection, electronic contract management, order data retention for 10 years (Accounting Law requirement) |
| Anti-Unfair Competition Law | 2019.04.23 | Market competition conduct regulation | Legal collection of public information for market analysis, no involvement of trade secrets |
| Advertising Law | 2018.11.29 | Advertising content and publication | Ensuring authenticity of content performance data, avoiding false advertising |
| AI Security Governance Framework | Reference standard | AI system security and auditability | AI orchestration decision logs retained for 2 years, ensuring explainability and audit trail |
II. Compliance Management Architecture
2.1 Organizational Structure
- Data Protection Officer (DPO): Overseeing overall data compliance management
- Legal & Compliance Department: Responsible for regulatory tracking, risk assessment, and compliance audits
- Information Security Department: Responsible for technical security implementation and security incident response
- Compliance Liaison for Each Business Module: Responsible for compliance execution within their respective modules
2.2 Compliance Coverage Across Nine Business Modules
This platform comprises 9 business modules, each implementing specific compliance measures based on actual data collection points. The following details data processing activities, data types, collection methods, retention periods, third-party sharing situations, and regulatory bases:
| Module | Data Processing Activities | Data Types | Collection Method | Retention Period | Third-Party Sharing | Compliance Measures & Regulatory Basis |
|---|---|---|---|---|---|---|
| Website Management (website) | Visitor browsing behavior tracking, Cookies & LocalStorage, contact/inquiry forms, quotation request forms | Behavioral data, technical data, personal information (name, contact details) | Cookies/tracking scripts, form submissions | Browsing behavior 2 years, Cookies 1 year, form data 3 years | No (no third-party sharing) | Cookie consent management (PIPL Article 13 consent); visitor data anonymization; form data used for business communication (PIPL Article 13 contract performance) |
| Intelligent Content (cortex) | AI content generation records, content publication and distribution data | Business data (generated content, distribution metrics) | AI API calls, tracking analytics | Generation records permanent (user-deletable), distribution data 3 years | Yes (AI content generation records shared with LLM service providers) | AI content labeling, manual review; separate consent required for third-party sharing (PIPL Article 23); compliance based on the Interim Measures for Generative AI |
| AI Engine (ai) | AI dialogue content, content sent to LLM for processing, model usage statistics | Personal information (dialogue content), business data (sent text), technical data (usage) | API calls | Dialogue content 180 days, LLM processing deleted immediately after, usage statistics 1 year | Yes (dialogue content and sent content shared with LLM providers) | Based on user consent (PIPL Article 13); Data Security Law requires important data not to leave the country; usage statistics used for monitoring and billing (legitimate interest) |
| Knowledge Base (kb) | Document uploads and knowledge base content, document vectorization and embedding | Business data (documents, vectors) | User uploads, AI vectorization | Permanent (user-deletable), vectors synchronized with source documents | Yes (vectorized embeddings may be shared with third-party AI infrastructure) | Access control, data encryption; agreements required for third-party sharing (Data Security Law); compliance based on PIPL Article 13 contract performance |
| Audience Nexus (nexus) | Member registration information, user profiling and behavioral tagging, user journey tracking | Personal information (name, phone number, etc.), behavioral tags, journey data | Forms, AI analysis, tracking | Registration information account duration + 3 years, behavioral tags 2 years, journey tracking 2 years | No (no third-party sharing) | Explicit consent (PIPL Article 13); users can disable personalized recommendations (Algorithmic Recommendation Management Provisions); pseudonymization of profiling data |
| Enterprise Office (office) | Business opportunity contact information, order and contract data, channel partner information | Personal information (contacts), financial data (amounts), business data (cooperation information) | Form entry, CRM system | Business opportunities 5 years, orders 10 years (Accounting Law requirement), channel cooperation duration + 3 years | No (no third-party sharing) | Minimum necessity principle; order data retained per Accounting Law; channel data based on contract performance (PIPL Article 13) |
| Beacon Optimization (beacon) | Monitoring of competitors' public data, algorithmic recommendations and personalization rules, sampled analysis of user behavior data | Business data (public information), algorithmic rules, behavioral data (desensitized) | API collection, AI learning, tracking | Public data 1 year, rules for duration of existence, behavioral sampling 1 year | No (no third-party sharing) | Only collection of legally public information (Anti-Unfair Competition Law); algorithm filing (Algorithmic Recommendation Provisions); behavioral data desensitized before analysis (PIPL Article 13 legitimate interest) |
| Operations Orchestrator (orchestrator) | AI orchestration decision logs | Technical data (decision records) | API logs | 2 years | No (no third-party sharing) | Auditability requirements (AI Security Governance Framework); logs used for troubleshooting and compliance audits |
| System Management (system) | User authentication and login credentials, email/SMS notification records | Personal information (account, password, phone number), operation logs | Forms, API calls | Account duration, notification records 180 days | Yes (authentication credentials shared with identity verification service providers; notification records shared with SMS/email service providers) | Real-name authentication (Cybersecurity Law); data processing agreements and user consent required for third-party sharing (PIPL Article 23) |
III. Compliance Policy System
- Privacy Impact Assessment (PIA): Conducted before launching new features, focusing on scenarios involving personal data processing
- Data Protection Impact Assessment (DPIA): Conducted prior to high-risk processing activities (e.g., AI dialogues, user profiling)
- Data Retention and Destruction Policy: Automated cleanup mechanisms established based on actual retention periods of each module (ranging from 180 days to permanent), with data anonymized or securely deleted upon expiration
- Third-Party Sharing Management: For modules involving third-party sharing (Intelligent Content, AI Engine, Knowledge Base, System Management), data processing agreements are signed to ensure third parties maintain equivalent security levels, and separate user consent is obtained
- Regular Compliance Audits: Internal compliance audits conducted semi-annually, covering actual data processing activities across all business modules
- Employee Training: Annual data security and privacy training for all employees, with emphasis on AI data processing standards
- Vendor Management: Data security assessments and agreements for third-party service providers, requiring compliance with PIPL, the Data Security Law, and other regulations
- Incident Response: Emergency response plans for data breaches and other security incidents, with investigation initiated within 24 hours and regulatory notification
IV. Legal Documentation System
This Compliance Center provides the following legal documents, constituting a comprehensive compliance disclosure system. Each document is prepared based on actual data collection points:
- Privacy Policy — Comprehensive explanation of personal information processing (covering all personal data collection points across modules)
- Terms of Service — Service usage agreements
- Cookie Policy — Management of Cookies and similar technologies
- Data Security Statement — Security measures and incident response
- AI Usage Statement — Transparency disclosure of AI technologies (dialogue data, content generation, etc.)
- Data Subject Rights — Guide for exercising user rights
- Intellectual Property Statement — Copyright and trademark protection
- Third-Party Services Statement — Data sharing recipients, purposes, and safeguards
- Children's Privacy Protection — Protection of minors' information
- Data Transfer Statement — Cross-border transfer compliance (if applicable)
V. Compliance Officer
Data Protection Officer (DPO):
Contact Email: www@mangxu.net
Contact Phone: 0516-87722111 (suggested to fill)
Office Address: Room 818, Building 2, Sanbao Plaza, Quanshan District, Xuzhou, Jiangsu Province
For compliance complaints and suggestions, please send to: xilu@139.com
If you have any questions regarding data processing or wish to exercise your data subject rights, please contact us through the channels above. We will respond as soon as possible.