Service Provider: Beijing Zhixue Yuanjian Management Consulting Co., Ltd.
Effective Date: July 10, 2025
Introduction
Beijing Zhixue Yuanjian Management Consulting Co., Ltd. (hereinafter referred to as "we" or "the Company") is well aware of the importance of personal privacy to you and will respect your privacy rights and ensure the security of your personal information. This Privacy Policy applies to all voice recognition products and services we provide (including hardware devices, cloud services, and related functions).
This policy will help you understand:
- How we collect and use your personal information
- How we store and protect your personal information
- How we use Cookies and similar technologies
- How we share, transfer, and disclose your personal information
- How you can manage your personal information
- How we protect minors' personal information
- How this policy is updated
- How to contact us
Important Reminders:
- Please read this Privacy Policy carefully before using our voice recognition services
- This policy specifically applies to sensitive information involving voice data processing
- Your use of our services indicates your consent to the contents of this policy
- This policy complies with applicable laws and regulations in your region
I. How We Collect and Use Your Personal Information
1.1 Definition of Personal Information
Personal information refers to various information recorded electronically or by other means that can identify a specific natural person's identity alone or in combination with other information, or reflect a specific natural person's activities. The definition of personal information may vary according to laws in different regions, and we comply with applicable laws in your region.
For voice recognition services, personal information mainly includes:
- Identity information: name, gender, age, ID document information
- Contact information: phone number, email address, mailing address
- Account information: username, password, security questions and answers
- Voice information: audio recordings, transcribed text, voice characteristic data
- Device information: device model, operating system, IP address, device identifier
- Usage information: service usage records, operation logs, preference settings
1.2 Information Collection Scenarios
(1) Account Registration and Authentication
Collected Information:
- Basic identity information (name, email, phone number)
- Account login information (username, password)
- Enterprise certification information for enterprise users
Usage Purposes:
- Create and manage user accounts
- Provide identity verification and account security protection
- Conduct user identity verification
- Provide customer service and technical support
Legal Basis:
- Necessity for performing service contracts
- Legitimate interest in protecting user account security
- Your explicit consent
- Other legal bases under applicable law
(2) Voice Recognition Services
Collected Information:
- Uploaded audio files
- Voice content in audio
- Text content generated by transcription
- Voice characteristic parameters (such as pitch, speech rate)
Usage Purposes:
- Provide voice recognition and transcription services
- Generate meeting records and intelligent summaries
- Improve voice recognition accuracy
- Provide personalized service experience
Legal Basis:
- Necessity for performing service contracts
- Your explicit consent
- Legitimate interest (service improvement)
Special Notes:
- We only process your voice data within the scope necessary for providing services
- Voice data will be stored or deleted according to your settings after processing is completed
- We will not use your voice data for training AI models (unless you explicitly consent)
- Voice characteristic data is considered biometric information and requires special protection, and can only be processed with your explicit consent
(3) Cloud Storage Services
Collected Information:
- Stored audio files
- Transcribed text and summary content
- File metadata (upload time, file size, format, etc.)
- File access records
Usage Purposes:
- Provide cloud storage and synchronization services
- Ensure data security and backup
- Provide multi-device access functionality
- Conduct data management and optimization
(4) Hardware Device Services
Collected Information:
- Device serial number, firmware version: only used for device identification and update push
- Device usage status (such as battery level, recording duration): only used for fault diagnosis, not associated with user identity information
- Device location information (optional): used for remote location function, users can turn it off in device settings, turning it off does not affect core recording functions
Usage Purposes:
- Provide device technical support and firmware updates
- Conduct device fault diagnosis and optimization
- (If user consents) Provide location assistance after device loss
(5) Paid Services
Collected Information:
- Payment information (order number, payment amount, payment method)
- Invoice information (invoice title, tax number, address)
- Transaction records and billing information
Usage Purposes:
- Process orders and payments
- Provide invoice services
- Conduct financial management
- Prevent fraud and risks
Note: We do not directly store your complete payment card information. Payment processing is completed by third-party payment institutions that comply with PCI DSS standards.
(6) Customer Service
Collected Information:
- Customer service communication records
- Problem feedback content
- Service evaluation information
- System diagnostic logs
Usage Purposes:
- Provide customer service and technical support
- Resolve user problems and complaints
- Improve service quality
- Conduct user satisfaction surveys
1.3 Information Usage Principles
Legality Principle:
- Collect and use information based on clear legal basis
- Will not process information beyond the scope necessary for services
- Comply with legal requirements in your region
Minimization Principle:
- Only collect information necessary for service functions
- Do not collect personal information unrelated to services
- Regularly evaluate the necessity of information collection
Transparency Principle:
- Clearly inform the purpose and use of information collection
- Provide clear privacy setting options
- Timely inform of policy changes
1.4 Sensitive Personal Information Processing
Biometric Information:
- Voice characteristic data belongs to biometric information
- Requires your explicit consent to process
- Only used for providing voice recognition services
- Encryption technology is used to protect data security
Other Sensitive Information:
- Meeting recordings may contain trade secrets
- Personal private conversation content
- Information involving others' privacy
Processing Principles:
- Obtain explicit separate consent
- Adopt stricter security measures
- Provide more detailed control options
- Conduct regular security audits
II. How We Store and Protect Your Personal Information
2.1 Data Storage
(1) Storage Location
Data Storage Principles:
- Comply with data localization requirements in various regions
- Prioritize storing data in your region or nearby regions
- Cross-border data transfer complies with relevant laws and regulations
- Ensure data storage complies with local legal requirements
Storage Locations:
- Chinese user data is mainly stored within China
- EU user data is stored within the EU or adequacy regions
- US user data is stored in the US or other compliant regions
- Other regional user data is stored in the nearest compliant data center
(2) Storage Period
General Storage Period:
- Account information: during account existence and necessary period after cancellation
- Voice data: users can choose storage period, not exceeding legal limits
- Transcribed text: users can manage themselves, support long-term storage or regular deletion
- Usage logs: stored according to local legal requirements, usually not exceeding 12 months
- Customer service records: storage period complies with local legal requirements
Special Circumstances:
- Information required by laws and regulations is handled according to legal requirements
- Information needed for dispute resolution is retained until dispute resolution is completed
- Information that users explicitly request to delete will be deleted immediately when technically feasible
Supplement:
After the storage space purchased by users expires, the system will send 3 reminders (7 days before expiration, on the day, 3 days after expiration). If not renewed after expiration, data will be retained for a 30-day buffer period, and will be automatically deleted after the buffer period. Users can pay to restore access or export data during the buffer period.
2.2 Data Security Protection
(1) Technical Measures
Encryption Protection:
- Data transmission uses TLS 1.3 or higher version encryption
- Data storage uses AES-256 or equivalent level encryption
- Voice data uses end-to-end encryption (when technically feasible)
- Database encrypted storage and access control
Access Control:
- Implement strict role-based access control
- Adopt multi-factor authentication
- Regularly audit access logs
- Principle of least privilege
System Security:
- Regularly conduct security vulnerability scanning and penetration testing
- Deploy firewalls and intrusion detection systems
- Real-time monitoring of abnormal access and activities
- Regularly update security patches
(2) Management Measures
Employee Management:
- All employees sign confidentiality agreements
- Regular security awareness training
- Implement job separation and division of responsibilities
- Strict data cleanup process upon departure
System Building:
- Establish comprehensive information security management system
- Develop data breach emergency response plan
- Conduct regular internal and external security audits
- Establish security incident reporting and handling mechanism
(3) Data Backup and Recovery
Backup Strategy:
- Implement automated data backup mechanism
- Multi-geographic location disaster recovery storage
- Regular backup recovery testing
- Fast recovery capability assurance
2.3 Data Security Incident Handling
Emergency Response:
- Immediately activate emergency response plan
- Timely control and assess security incident impact
- Investigate incident cause and scope of impact
- Report to relevant regulatory authorities as required by applicable law
User Notification:
- Notify affected users within the time required by law
- Explain the nature of the incident, possible impact, and measures taken
- Provide preventive measure suggestions that users can take
- Regularly update incident handling progress
III. How We Use Cookies and Similar Technologies
3.1 Cookie Technology
(1) Use of Cookies
Definition: Cookies are small text files stored on your device, used to improve user experience and service functionality.
Usage Purposes:
- Remember your login status and preference settings
- Provide personalized user experience
- Analyze website usage and performance
- Improve service quality and functionality
- Provide security protection (such as fraud prevention)
Cookie Types:
- Essential Cookies: Basic functions to ensure normal website operation
- Performance Cookies: Collect anonymous statistical information on website usage
- Functional Cookies: Remember user choices and preference settings
- Analytics Cookies: Help us understand how users use our services
(2) Cookie Management
User Control:
- You can manage Cookies through browser settings
- Choose to accept, reject, or delete specific types of Cookies
- Set Cookie acceptance policies and expiration times
- Clear stored Cookies
Disabling Impact:
- Disabling essential Cookies may cause some functions to not work properly
- Disabling functional Cookies may require resetting personal preferences
- Disabling analytics Cookies will not affect service functionality
3.2 Other Technologies
(1) Web Beacons
Usage Purposes:
- Understand email opening and reading status
- Analyze user behavior patterns
- Optimize content and services
- Provide technical support
(2) Log Files
Collected Information:
- IP address and access time
- Browser type and version information
- Operating system and device information
- Pages visited and function usage
- Referral source information
Usage Purposes:
- System operation and maintenance and fault diagnosis
- Security monitoring and threat protection
- User behavior analysis and service optimization
- Performance monitoring and improvement
IV. How We Share, Transfer, and Disclose Your Personal Information
4.1 Information Sharing
(1) Situations Where We Will Not Actively Share
We Promise:
- Will not sell your personal information to any third party
- Will not disclose your voice content to third parties (unless required by law or with your explicit consent)
- Will not share your sensitive information for commercial marketing purposes
- Will not provide your identity information to third parties without consent
(2) Possible Sharing Situations
Service Provision:
- Share necessary technical data with cloud service providers to provide storage and computing services
- Share payment-related information with payment institutions to process transactions
- Share delivery information with logistics companies to deliver hardware products
- Share service records with customer service system suppliers to provide customer support
Legal Requirements:
- Situations where laws and regulations explicitly require disclosure
- Legitimate requirements from judicial or administrative authorities
- Emergency situations to protect user or public safety
- Necessary situations to protect our legitimate rights and interests
Business Cooperation:
- Share necessary information with authorized partners to provide joint services
- Information transfer during business integration, merger, or acquisition
- Necessary information sharing when providing joint products or services
- Other cooperation scenarios with user's explicit consent
4.2 Cross-Border Data Transfer
(1) Transfer Principles
Compliance Requirements:
- Comply with laws and regulations related to data export
- Comply with legal requirements of destination countries or regions
- Ensure the security and legality of data transfer
- Protect user data rights from damage
Security Assurance:
- Sign data processing agreements with overseas recipients
- Require overseas recipients to adopt equivalent security measures
- Regularly assess risks of overseas data processing
- Establish monitoring mechanism for cross-border data transfer
(2) Transfer Scenarios
Possible Transfer Situations:
- Provide localized services for international users
- Use international cloud services for data processing and storage
- Conduct necessary technical collaboration with foreign technology partners
- Participate in international standard setting and technical exchange
4.3 Information Disclosure
(1) Active Disclosure
Public Information:
- Information that users actively choose to make public
- Information that laws explicitly require to be made public
- Information that users explicitly consent to make public
(2) Passive Disclosure
Legal Requirements:
- Requirements of court judgments, rulings, or mediation documents
- Requirements of arbitration institution rulings
- Decisions or orders of administrative authorities
- Requirements of other legal procedures
Emergency Situations:
- Protect the life, health, and property safety of users or others
- Maintain public safety and national security
- Prevent major illegal and criminal activities
- Necessary disclosure in other emergency situations
4.4 Third-Party Cloud Service Data Processing
(1) Cloud Service Usage
Third-Party Cloud Services We Use:
- Cloud Computing Services: Alibaba Cloud, Tencent Cloud, AWS, Azure, OpenAI, etc., used to run voice recognition algorithms
- Cloud Storage Services: Used to store audio files and transcribed text uploaded by users
- Database Services: Used to store user information and business data
- Content Delivery Network (CDN): Used to improve service access speed and stability
- Security Services: Used for data encryption, access control, and threat protection
Usage Reasons:
- Provide stable and reliable technical infrastructure
- Ensure high availability and scalability of services
- Utilize professional security protection and backup mechanisms
- Provide better service experience for users
(2) Data Processing Agreement and Division of Responsibilities
Compliance Assurance:
- Sign Data Processing Agreements (DPA) with all third-party cloud service providers
- Require cloud service providers to comply with the same data protection standards as us
- Clearly agree on the purpose, scope, and period of data processing
- Establish notification and handling mechanism for data security incidents
Division of Responsibilities:
- Cloud service providers are responsible for: infrastructure security, physical security, network security
- We are responsible for: logical access control of data, application layer security, user permission management
- Jointly responsible for: legal liability for data protection, security audits and assessments
- Supervision mechanism: regularly audit cloud service providers' security measures and compliance status
(3) Cloud Data Security Protection
Technical Assurance:
- All data uses TLS 1.3 encryption during transmission
- Data in cloud storage uses AES-256 encryption
- Implement multi-factor authentication and access control
- Regularly conduct data backup and disaster recovery testing
Management Assurance:
- Strictly limit cloud service provider employees' access to data
- Require cloud service providers to provide detailed data access logs
- Establish rapid response and notification mechanism for data breaches
- Regularly assess cloud service providers' security measures and compliance status
(4) Data Location and Cross-Border Processing
Data Storage Location:
- Chinese Users: Data is mainly stored in data centers within China
- EU Users: Data is stored within the EU or adequacy regions
- US Users: Data is stored in the US or other compliant regions
- Other Regions: Data is stored in the nearest compliant data center
Cross-Border Transfer Control:
- Strictly control cross-border data transfer, only when necessary
- Ensure destination has adequate data protection level
- Establish approval and monitoring mechanism for cross-border data transfer
- Comply with data localization requirements in various regions
(5) User Control Over Cloud Services
Transparency Assurance:
- Users have the right to know which third-party cloud services are specifically used
- Provide basic information about cloud service providers and data processing methods
- Explain the storage period and processing scope of data in cloud services
- Regularly update the usage of third-party service providers
User Control Options:
- Users can choose data storage region (when technically feasible)
- Provide data export function to support user self-management of data
- Ensure complete deletion of cloud data when users cancel accounts
- Support users to choose specific cloud service providers when technically feasible
(6) Cloud Service Provider Change Management
Change Notification:
- Notify users 30 days before changing major cloud service providers
- Explain the reasons for the change and the impact on user data processing
- Provide specific arrangements and timetable for data migration
- Ensure data security and service continuity during the change process
User Rights Protection:
- Users can choose not to agree to service provider changes
- Provide data export services to support users to migrate to other services
- Give users sufficient consideration time before the change takes effect
- Respect users' reasonable requests and feedback
V. How You Can Manage Your Personal Information
5.1 User Rights
(1) Right of Access
You Have the Right to:
- Understand the types of personal information we collect and processing activities
- View the processing purposes and legal basis of personal information
- Understand the storage period and third-party sharing of information
- Obtain copies of personal information (within technically feasible scope)
- Understand which third-party cloud services your data is stored in
Exercise Methods:
- View basic information through user backend
- Contact customer service to obtain detailed information reports
- Submit written applications to obtain complete information
- Use data export function to download personal data
(2) Right of Correction
You Have the Right to:
- Correct inaccurate or outdated personal information
- Supplement incomplete personal information
- Update changed personal information
- Correct erroneous personal information
Operation Methods:
- Log in to account to directly modify basic information
- Contact customer service to assist in correcting complex information
- Provide relevant supporting materials to support correction requests
- Automatically update some information through the system
(3) Right of Deletion
You Have the Right to Request Deletion of:
- Personal information that has exceeded the storage period
- Information processed based on consent and you have withdrawn consent
- Personal information we have illegally processed
- Other information you have the right to delete according to law
Deletion Scope:
- All relevant data in our systems
- Your data stored in third-party cloud services
- Relevant data in backup systems (within technically feasible scope)
- Personal identification information in log files
Deletion Restrictions:
- Information required by laws and regulations
- Information necessary for contract performance
- Information needed for exercising legal rights or legal defense
- Information necessary for protecting others' legitimate rights and interests
(4) Right to Withdraw Consent
You Have the Right to:
- Withdraw consent for specific information processing activities
- Choose different scopes of consent content
- Modify previously given consent conditions
- Re-decide specific content of consent
Notes:
- Withdrawal of consent does not affect the legality of processing based on consent before withdrawal
- Withdrawal of consent may affect the use of certain service functions
- After withdrawal, we will stop related information processing activities
- Processing based on other legal bases is not affected by withdrawal of consent
(5) Right to Data Portability
You Have the Right to:
- Obtain personal information you have provided to us
- Request transfer of data to other service providers
- Obtain data copies in structured, commonly used formats
- Achieve data migration when technically feasible
5.2 Privacy Settings
(1) Voice Data Management
Storage Settings:
- Choose voice data storage period (1 month to 3 years)
- Set automatic deletion rules and reminders
- Decide whether to allow cloud storage and backup
- Choose the device range for data synchronization
- Choose data storage geographic location (when technically feasible)
Usage Settings:
- Control specific usage purposes of voice data
- Set the scope of data analysis and processing
- Decide whether to participate in service improvement and optimization
- Choose the degree and type of personalized services
(2) Notification Settings
Notification Types:
- Service updates and feature release notifications
- Security reminders and abnormal activity notifications
- Product recommendations and marketing information
- Important account-related notifications
- Third-party cloud service change notifications
Control Options:
- Choose notification methods (email, SMS, app push)
- Set notification frequency and time
- Decide specific content types of notifications received
- Manage notification priority and importance
(3) Privacy Protection Settings
Data Processing Control:
- Choose data processing geographic location
- Set data encryption and security level
- Control participation in data analysis and statistics
- Manage third-party service access permissions
- Control cloud service provider data processing permissions
5.3 Account Cancellation
(1) Cancellation Process
Pre-Cancellation Preparation:
- Confirm account identity and ownership
- Backup important data that needs to be retained
- Handle incomplete orders and services
- Understand the impact and consequences after cancellation
Cancellation Steps:
- Select cancellation option in account settings
- Confirm cancellation intent through identity verification
- Choose data processing method (deletion or anonymization)
- Confirm cancellation and wait for processing to complete
(2) Consequences of Cancellation
Data Processing:
- Immediately stop processing your personal information
- Delete or anonymize stored data
- Notify third-party cloud service providers to delete relevant data
- Retain information that must be retained by law
- Completely terminate service relationship with you
Service Impact:
- Cannot continue to use any service functions
- Permanently lose historical data and usage records
- Cloud functions of related hardware devices are limited
- Cancel all membership rights and services
VI. How We Protect Minors' Personal Information
6.1 Age Restrictions and Special Protection
Service Targets:
- Our services are mainly for adults and business users
- Children under 14 years old may not use our services independently
- Minors aged 14-18 need guardian's informed consent
- Some advanced features may have higher age requirements
Special Protection Measures:
- Adopt stricter collection restrictions for minors' information
- Do not collect unnecessary sensitive information of minors
- Process only after obtaining guardian's explicit consent
- Regularly evaluate the necessity of collecting minors' information
6.2 Guardian Rights
Guardians Have the Right to:
- View and correct minors' personal information
- Request deletion of unnecessary minors' information
- Withdraw consent for processing minors' information
- Supervise minors' use of services
Exercise Methods:
- Contact our customer service team
- Provide proof of guardianship relationship
- Exercise relevant rights through written application
- Participate in decisions on minors' information protection
VII. How This Policy Is Updated
7.1 Update Principles and Situations
Update Trigger Situations:
- Significant changes in relevant laws and regulations
- Major adjustments to our business model or service functions
- Important changes in data processing methods
- Need to strengthen user rights protection
- Important changes in third-party cloud service providers
Update Principles:
- Ensure updated policy complies with latest legal requirements
- Fully consider user rights and reasonable expectations
- Maintain clarity and understandability of the policy
- Balance business needs and privacy protection
7.2 Update Procedures
Internal Procedures:
- Internal legal and business teams evaluate update needs
- Draft update content and conduct compliance checks
- Assess impact of updates on users
- Senior management approves update content
External Procedures:
- Publish update notifications through multiple channels
- Provide users with sufficient time to view and consider
- Collect user feedback and make necessary adjustments
- Formally implement updated policy
7.3 Notification Methods
Notification Channels:
- Publish announcements on our official website
- Send notifications to registered users via email
- Push important update information within mobile applications
- Remind important policy changes via SMS
Notification Content:
- Specific content and reasons for updates
- Effective time and applicable scope of updates
- Impact of updates on user rights and obligations
- Actions users can take accordingly
VIII. Dispute Resolution and Contact Information
8.1 Contact Information
Contact Channels:
Customer Service Email: info@pulaoecho.com
Processing Commitments:
- Confirm receipt of your complaint within 24 hours
- Provide preliminary response within 5 working days
- Complete investigation and provide processing results within 15 working days
- Timely feedback on processing progress and final results
8.2 Dispute Resolution and Regulatory Complaints
Internal Appeals:
- For privacy-related issues, please contact: info@pulaoecho.com first
- We promise to take every privacy complaint seriously
- Provide fair and timely internal appeal handling mechanism
- Respect users' legitimate rights and reasonable demands
External Regulation:
- You have the right to complain to data protection regulatory authorities in your region
- Regulatory authorities and complaint procedures may vary in different regions
- If you need to know specific complaint channels, we can provide guidance
- We promise to cooperate with regulatory authorities' investigations and handling
Legal Remedies:
- You can seek judicial remedies according to local laws
- We promise to treat and handle every user's reasonable demands with sincerity
- We respect judicial jurisdiction and dispute resolution mechanisms in various regions
- Dispute resolution prioritizes applicable laws and regulations in your region
- We promise to cooperate with judicial authorities' investigations and enforcement
International Arbitration (if applicable):
- For cross-border disputes, international arbitration can be chosen
- Specific arbitration methods and locations are according to contract agreements
- We promise to fully cooperate with legitimate arbitration procedures
- Execute arbitration results and protect users' legitimate rights and interests
Appendix: Important Concept Explanations
Personal Information: Various information recorded electronically or by other means that can identify a specific natural person's identity alone or in combination with other information, or reflect a specific natural person's activities.
Sensitive Personal Information: Personal information that, once leaked or illegally used, may easily lead to infringement of a natural person's dignity or endanger personal or property safety.
Biometric Information: Personal information with biological characteristics, such as fingerprints, voiceprints, irises, facial features, etc.
Voice Data: Information related to voice recognition, including original audio files, voice characteristic parameters, transcribed text, etc.
De-identification: The process of technical processing of personal information so that it cannot identify a specific natural person without additional information.
Anonymization: The process of technical processing of personal information so that the personal information subject cannot be identified and cannot be restored.
Cross-Border Data Transfer: The activity of transferring personal information from one country or region to another country or region.
Data Processing: Activities including collection, storage, use, processing, transmission, provision, and disclosure of personal information.
Data Controller: A natural person, legal person, or other organization that determines the purpose and method of personal information processing.
Data Processor: A natural person, legal person, or other organization that processes personal information on behalf of the data controller.
Cloud Service Provider: A third-party technology company that provides cloud computing, cloud storage, and other services.
Data Processing Agreement (DPA): An agreement signed with third-party service providers regarding data processing methods, security requirements, etc.
Appendix B: List of Third-Party Cloud Service Providers Currently Used
Main Cloud Service Providers:
- Alibaba Cloud Computing Co., Ltd.
- Tencent Cloud Computing (Beijing) Co., Ltd.
- Amazon Web Services (China) Co., Ltd.
- Microsoft (China) Co., Ltd.
Specific Service Content:
- Cloud servers and computing resources
- Cloud storage and database services
- Content distribution and network acceleration
- Security protection and monitoring services
Data Processing Locations:
- Mainland China: Data centers in Beijing, Shanghai, Shenzhen, etc.
- Overseas users: Nearest compliant data center
- Specific locations can be queried through customer service
Update Notes:
- This list will be updated according to business needs
- Important changes will be notified to users in advance
- The latest list can be queried through the official website
Thank you for reading our Privacy Policy!
We are well aware of the importance of privacy protection and promise to handle your personal information with transparency and responsibility. If you have any questions or suggestions, please feel free to contact us.
This Privacy Policy was last updated on: July 10, 2025
This Privacy Policy takes effect on: July 10, 2025
Beijing Zhixue Yuanjian Management Consulting Co., Ltd. reserves the right to revise this policy within the scope permitted by law.