Data Processing Agreement (DPA)

Last updated: 2026-08-14

1. Purpose

This Data Processing Agreement applies when the Platform acts as a data processor for enterprise customers, and forms an integral part of the master services agreement.

2. Scope of processing

Processed data is limited to: customer-uploaded brand information, monitored keywords, content assets, knowledge base documents, lead data and derived analytics, solely to deliver subscribed services.

3. Security obligations

The Platform commits to industry-standard technical and organizational measures: TLS transport encryption, AES-256 static encryption, access control and multi-tenant isolation, multi-factor authentication, audit logging, data backup and recovery, and on-request security attestation.

4. Sub-processors and transfers

The Platform may engage AI engine providers (domestic and overseas model services) to process necessary data; the sub-processor list is in the Privacy Policy. Cross-border transfers follow PIPL mechanisms (standard contractual clauses / security assessment).

5. Data subject assistance

The Platform will assist customers in responding to end-user data subject requests (access, correction, deletion, export) with necessary technical support.

6. Liability and audit

The Platform bears legal liability for breaches caused by its own fault. Customers may audit the Platform's processing activities with reasonable notice and a signed NDA.