Шарҳи риоя

合规总览

芒旭软件严格遵守《个人信息保护法》,为您提供透明的个人信息收集、使用和保护政策,保障您的数据主体权利。

Версия v1Санаи эътибор2026/05/13Охирин навсозӣ2026/08/09

Legal & Compliance Overview

Last updated:2026-06-05

Xuzhou Mangxu Software Technology Co., Ltd. (hereinafter referred to as "Mangxu Software"), as an enterprise-level AI intelligent operation platform, deeply recognizes the importance of data compliance and legal standardization. We have established a compliance management system covering the entire business chain, ensuring that platform operations comply with Chinese laws and regulations, and continuously optimizing compliance measures based on actual data processing activities.

Regulation NameEffective DateApplicable DomainCorresponding Platform Measures
Personal Information Protection Law (PIPL)2021.11.01Full lifecycle of personal information processingPrivacy policy, data subject rights, consent management; specifically based on Article 13 of PIPL (legal basis), Article 17 (obligation to inform), Article 23 (separate consent for third-party sharing), etc.
Data Security Law2021.09.01Data classification, grading, and security protectionData tiered management, security assessments, emergency response; directory-based protection for important data (e.g., knowledge base content)
Cybersecurity Law2017.06.01Network operation security and information securityClassified protection, log retention (not less than 6 months), security incident reporting; real-name authentication requirements
Internet Information Service Algorithmic Recommendation Management Provisions2022.03.01Algorithmic recommendation service managementAlgorithm filing, recommendation transparency, user choice (ability to disable personalized recommendations)
Interim Measures for the Management of Generative Artificial Intelligence Services2023.08.15Generative AI service managementAI content labeling, usage declarations, security assessments; dialogue data retention not exceeding 180 days
Provisions on the Protection of Children's Personal Information Online2019.10.01Protection of information of children under 14Children's privacy protection policy, age verification mechanism
Measures for Security Assessment of Data Export2022.09.01Cross-border data transfer managementLocalized data storage, security assessment required before transfer
E-Commerce Law2019.01.01E-commerce activity regulationConsumer rights protection, electronic contract management, order data retention for 10 years (Accounting Law requirement)
Anti-Unfair Competition Law2019.04.23Market competition conduct regulationLegal collection of public information for market analysis, no involvement of trade secrets
Advertising Law2018.11.29Advertising content and publicationEnsuring authenticity of content performance data, avoiding false advertising
AI Security Governance FrameworkReference standardAI system security and auditabilityAI orchestration decision logs retained for 2 years, ensuring explainability and audit trail

II. Compliance Management Architecture

2.1 Organizational Structure

  • Data Protection Officer (DPO): Overseeing overall data compliance management
  • Legal & Compliance Department: Responsible for regulatory tracking, risk assessment, and compliance audits
  • Information Security Department: Responsible for technical security implementation and security incident response
  • Compliance Liaison for Each Business Module: Responsible for compliance execution within their respective modules

2.2 Compliance Coverage Across Nine Business Modules

This platform comprises 9 business modules, each implementing specific compliance measures based on actual data collection points. The following details data processing activities, data types, collection methods, retention periods, third-party sharing situations, and regulatory bases:

ModuleData Processing ActivitiesData TypesCollection MethodRetention PeriodThird-Party SharingCompliance Measures & Regulatory Basis
Website Management (website)Visitor browsing behavior tracking, Cookies & LocalStorage, contact/inquiry forms, quotation request formsBehavioral data, technical data, personal information (name, contact details)Cookies/tracking scripts, form submissionsBrowsing behavior 2 years, Cookies 1 year, form data 3 yearsNo (no third-party sharing)Cookie consent management (PIPL Article 13 consent); visitor data anonymization; form data used for business communication (PIPL Article 13 contract performance)
Intelligent Content (cortex)AI content generation records, content publication and distribution dataBusiness data (generated content, distribution metrics)AI API calls, tracking analyticsGeneration records permanent (user-deletable), distribution data 3 yearsYes (AI content generation records shared with LLM service providers)AI content labeling, manual review; separate consent required for third-party sharing (PIPL Article 23); compliance based on the Interim Measures for Generative AI
AI Engine (ai)AI dialogue content, content sent to LLM for processing, model usage statisticsPersonal information (dialogue content), business data (sent text), technical data (usage)API callsDialogue content 180 days, LLM processing deleted immediately after, usage statistics 1 yearYes (dialogue content and sent content shared with LLM providers)Based on user consent (PIPL Article 13); Data Security Law requires important data not to leave the country; usage statistics used for monitoring and billing (legitimate interest)
Knowledge Base (kb)Document uploads and knowledge base content, document vectorization and embeddingBusiness data (documents, vectors)User uploads, AI vectorizationPermanent (user-deletable), vectors synchronized with source documentsYes (vectorized embeddings may be shared with third-party AI infrastructure)Access control, data encryption; agreements required for third-party sharing (Data Security Law); compliance based on PIPL Article 13 contract performance
Audience Nexus (nexus)Member registration information, user profiling and behavioral tagging, user journey trackingPersonal information (name, phone number, etc.), behavioral tags, journey dataForms, AI analysis, trackingRegistration information account duration + 3 years, behavioral tags 2 years, journey tracking 2 yearsNo (no third-party sharing)Explicit consent (PIPL Article 13); users can disable personalized recommendations (Algorithmic Recommendation Management Provisions); pseudonymization of profiling data
Enterprise Office (office)Business opportunity contact information, order and contract data, channel partner informationPersonal information (contacts), financial data (amounts), business data (cooperation information)Form entry, CRM systemBusiness opportunities 5 years, orders 10 years (Accounting Law requirement), channel cooperation duration + 3 yearsNo (no third-party sharing)Minimum necessity principle; order data retained per Accounting Law; channel data based on contract performance (PIPL Article 13)
Beacon Optimization (beacon)Monitoring of competitors' public data, algorithmic recommendations and personalization rules, sampled analysis of user behavior dataBusiness data (public information), algorithmic rules, behavioral data (desensitized)API collection, AI learning, trackingPublic data 1 year, rules for duration of existence, behavioral sampling 1 yearNo (no third-party sharing)Only collection of legally public information (Anti-Unfair Competition Law); algorithm filing (Algorithmic Recommendation Provisions); behavioral data desensitized before analysis (PIPL Article 13 legitimate interest)
Operations Orchestrator (orchestrator)AI orchestration decision logsTechnical data (decision records)API logs2 yearsNo (no third-party sharing)Auditability requirements (AI Security Governance Framework); logs used for troubleshooting and compliance audits
System Management (system)User authentication and login credentials, email/SMS notification recordsPersonal information (account, password, phone number), operation logsForms, API callsAccount duration, notification records 180 daysYes (authentication credentials shared with identity verification service providers; notification records shared with SMS/email service providers)Real-name authentication (Cybersecurity Law); data processing agreements and user consent required for third-party sharing (PIPL Article 23)

III. Compliance Policy System

  • Privacy Impact Assessment (PIA): Conducted before launching new features, focusing on scenarios involving personal data processing
  • Data Protection Impact Assessment (DPIA): Conducted prior to high-risk processing activities (e.g., AI dialogues, user profiling)
  • Data Retention and Destruction Policy: Automated cleanup mechanisms established based on actual retention periods of each module (ranging from 180 days to permanent), with data anonymized or securely deleted upon expiration
  • Third-Party Sharing Management: For modules involving third-party sharing (Intelligent Content, AI Engine, Knowledge Base, System Management), data processing agreements are signed to ensure third parties maintain equivalent security levels, and separate user consent is obtained
  • Regular Compliance Audits: Internal compliance audits conducted semi-annually, covering actual data processing activities across all business modules
  • Employee Training: Annual data security and privacy training for all employees, with emphasis on AI data processing standards
  • Vendor Management: Data security assessments and agreements for third-party service providers, requiring compliance with PIPL, the Data Security Law, and other regulations
  • Incident Response: Emergency response plans for data breaches and other security incidents, with investigation initiated within 24 hours and regulatory notification

This Compliance Center provides the following legal documents, constituting a comprehensive compliance disclosure system. Each document is prepared based on actual data collection points:

  • Privacy Policy — Comprehensive explanation of personal information processing (covering all personal data collection points across modules)
  • Terms of Service — Service usage agreements
  • Cookie Policy — Management of Cookies and similar technologies
  • Data Security Statement — Security measures and incident response
  • AI Usage Statement — Transparency disclosure of AI technologies (dialogue data, content generation, etc.)
  • Data Subject Rights — Guide for exercising user rights
  • Intellectual Property Statement — Copyright and trademark protection
  • Third-Party Services Statement — Data sharing recipients, purposes, and safeguards
  • Children's Privacy Protection — Protection of minors' information
  • Data Transfer Statement — Cross-border transfer compliance (if applicable)

V. Compliance Officer

Data Protection Officer (DPO):
Contact Email: www@mangxu.net
Contact Phone: 0516-87722111 (suggested to fill)
Office Address: Room 818, Building 2, Sanbao Plaza, Quanshan District, Xuzhou, Jiangsu Province

For compliance complaints and suggestions, please send to: xilu@139.com

If you have any questions regarding data processing or wish to exercise your data subject rights, please contact us through the channels above. We will respond as soon as possible.