01Scope, operator and contact
This policy explains personal data processing for Abelien websites and workspaces offering accounts, projects, resources, generation, sharing and the payment features actually enabled. The operator in China is 深圳芯互链智能科技有限公司. International services use the Abelien.ai brand. Unless a feature clearly identifies another legal entity before processing, this operator is responsible for the processing described here. Privacy and rights requests: wangyizheng@abelien.cn.
This policy covers actual processing and does not activate unavailable features. When we process organizational data on a business customer’s instructions, a separate data processing agreement may also apply. End users may also contact their organization’s administrator.
02Categories, sources and purposes
We receive information you submit, information from identity providers you authorize, and necessary technical information generated by use. The information needed varies by region and enabled feature.
| Category | Examples | Purpose |
|---|---|---|
| Account and sign-in | Submitted phone or email, provider identifier, authorized profile and verification results | Identify accounts, verify sign-in and recover access |
| Creation and projects | Prompts, conversations, reference images, files, models, versions and actions | Carry out requests, save and resume work, preview and export |
| Workspaces and sharing | Membership, roles, permissions and work you choose to publish | Collaboration, access control and sharing you request |
| Orders and transactions | Order identifier, amount, currency, status and provider transaction verification | Billing, order status, refunds, accounting and legal duties |
| Technical and security | IP address, browser and device information, request time, necessary access and error records | Deliver content, protect security, prevent abuse and diagnose problems |
| Communications and requests | Contact details, descriptions and necessary identity checks you submit | Support, complaints and privacy rights requests |
Payment providers process payment credentials under their own rules. Do not enter card security codes, payment passwords, verification codes or unrelated personal data in prompts or support emails. Public availability does not give us an unrestricted right to use personal data.
03Legal bases and choices
Under applicable Chinese law, processing relies on necessity for the contract you request, legal obligations, valid consent or another basis allowed by law. Optional purposes are distinct from the basic service. Reading this policy, signing in or accepting general terms does not replace separate or written consent where required.
Where GDPR or UK data protection law applies, requested account and project services generally rely on contractual necessity; tax and legally required records on legal obligations; and security, fraud prevention and legal claims may rely on legitimate interests following a necessity and balancing assessment. Optional marketing and non-essential cookies rely on consent where required. You may withdraw consent or object to legitimate-interest processing. Refusing optional processing does not prevent basic features that do not depend on it.
04Cookies, browser storage and measurement
Workspaces may use necessary session and security-state cookies and browser storage for sign-in, provider callbacks, abuse prevention and unsynchronized inputs. The existing Workspace session cookie lasts 12 hours; temporary OAuth state lasts 5 minutes. Independent services with other durations should disclose them at collection.
Browser controls let you clear or block storage, which may sign you out or discard unsynchronized content. Signing out does not delete server accounts or projects. Non-essential analytics, advertising or tracking that legally requires consent should have a separate choice before activation; this policy does not authorize default activation.
The legal center itself sets no cookies, uses no browser storage and loads no third-party analytics or advertising scripts. Hosting and network services still process necessary request information. Advertising opt-out actions are unnecessary on these static pages. Applicable sale or sharing opt-out signals, including Global Privacy Control, should be respected in the relevant product under applicable rules; a Do Not Track header does not by itself provide blanket consent.
05AI tools, inputs and training
Using an enabled AI or generation tool may transmit the necessary prompt, reference material or model information to its provider to perform your request. Providers may operate in China or elsewhere and have different retention, safety-review and data-use rules. Understand the provider identified for the feature before submitting and avoid unnecessary personal data, sensitive data and unauthorized trade secrets.
This policy does not grant us permission to use your private work or inputs containing personal data to train publicly offered foundation models. An additional purpose requires clear separate notice and legally required authorization. Our policy is not a guarantee that all third-party model providers never retain inputs or use data for training.
06Providers and recipients
The following services apply to relevant deployments or enabled features; not every request is sent to every recipient. Entrusted processing should be restricted by necessary contracts and security measures. Disclosure to independent controllers, publication or other processing requiring additional notice should be preceded by specific notice and any legally required consent.
| Service / recipient | Role and potential information | Location |
|---|---|---|
| Alibaba Cloud | Hosting, storage, DNS and enabled SMS verification; technical requests, stored content or SMS destination | This legal center is hosted in Hangzhou, China; business-data locations depend on deployment |
| Volcengine / Ark | Enabled resources, storage and model services; relevant files or generation requests | Depends on the selected resource and service region |
| Vercel | Hosting and requests for websites deployed on its platform | May involve processing outside China; page language does not establish location |
| Google sign-in you choose and the information you authorize | May involve overseas identity services; see the authorization and Google notices | |
| WeChat / WeChat Pay | Selected sign-in, payment or status checks; authorized identity or necessary order information | Depends on the enabled channel and provider rules |
| The particular AI / 3D tool provider | Necessary inputs for the requested generation task | Identify the actual recipient, region and rules for the enabled tool |
Contact wangyizheng@abelien.cn for specific recipients, purposes, categories and transfer arrangements relevant to your features. A provider category does not replace a legally required specific notice. Processing should not proceed where required notice, consent or other legal conditions have not been fulfilled.
07Disclosure, publication and business changes
Information may be processed by restricted service providers as necessary to deliver the service, or shown to members, sharing recipients or the public as you expressly choose. This policy does not authorize selling personal data or sharing it for cross-context behavioral advertising.
Necessary disclosures may be made under law, for safety or to address legitimate disputes. A merger, reorganization or change of operator involving personal data should be accompanied by required notice identifying the recipient and contact, with applicable protections maintained. Materially changed purposes require legally required authorization.
08Locations and international transfers
Chinese and international service data locations cannot be inferred from interface language. Some existing resources are in China; overseas hosting, identity and model services may involve international processing. These legal pages are hosted on Alibaba Cloud in Hangzhou, China. This does not establish the location of all business data.
Transfers of Chinese personal information require applicable notices, separate consent, impact assessments and, as applicable, a security assessment, standard contract, certification or another lawful route. An exemption from a particular transfer procedure does not automatically waive other duties. EEA, UK or Swiss transfers require an applicable adequacy decision, valid contractual safeguards such as standard contractual clauses or the UK Addendum / IDTA, or another valid mechanism and necessary assessments.
This policy does not certify completion of those mechanisms for every provider or region, and general acceptance is not transfer authorization. A transfer should not proceed without its applicable legal conditions. Email us about destinations, recipients, safeguards and legally available documentation.
09Retention and deletion
Data is retained for the shortest period necessary for its purpose, considering an active account, projects you retain, unsettled orders, legal record requirements and real disputes. Account and project information is generally retained while the corresponding service is provided. A deletion or closure request should lead to review and deletion or anonymization of information no longer needed.
Security, support, order and accounting records are handled according to their purpose and applicable retention requirements. Known session and OAuth durations are listed above. Production log, backup and provider-copy deletion cycles can vary by deployment; contact us for details. We do not promise immediate removal of every copy.
If legal retention, a valid dispute or technical constraints temporarily prevent deletion, processing should be restricted to necessary storage and security, not unrelated purposes. Backups should expire through their regular cycle, and confirmed deletion restrictions should be reapplied after restoration.
10Security and incidents
Risk-appropriate safeguards should include access controls, protected transport, necessary permission separation and security reviews. Protect your credentials, share cautiously and report unusual activity. No network service can promise absolute security.
A personal data incident should be contained, documented and reported to authorities or affected individuals when required by applicable law. Routine diagnostics should not collect unnecessary passwords, verification codes or full payment credentials.
11Rights and how to request them
Depending on applicable law, you may request information and access, a copy, correction, deletion, restriction, objection, withdrawal of consent, account closure and, where applicable, portability. For automated decisions with significant effects, you may request an explanation and legally available human review. Creative suggestions should not be the sole determinant of a significant matter about you.
Email wangyizheng@abelien.cn with the request and necessary account identifiers. Identity checks should be proportionate to the risk; full identity documents or passwords should not be required by default. Legally authorized agents may submit requests. If a request cannot be fulfilled, the reason and available complaint route should be explained. Exercising rights should not lead to unlawful discrimination.
Requests should be handled promptly within local legal deadlines. GDPR requests are generally answered within one month; any lawful extension is explained within that first month. Applicable California access, correction and deletion requests generally receive a substantive response within 45 days, with lawful extensions explained. Sale or sharing opt-outs follow their shorter applicable deadline. Chinese requests should be handled promptly under applicable law without using a general deadline to limit a faster legal requirement.
12Additional information for China
Where Chinese personal information law applies, rights include knowing, deciding, restricting or refusing processing; accessing and copying data; correction, supplementation and deletion; and explanations of processing rules. Necessary contractual or legal processing must be distinguished from optional consent-based processing.
Sensitive personal information should only be processed for a specific and sufficiently necessary purpose with required separate consent, notice of necessity and effects, and safeguards. Information about children under 14 requires guardian consent and special rules. Creative inputs do not require sensitive information or information about children.
13Additional information for Europe, the UK and Switzerland
Where the relevant law applies, rights include access, correction, erasure, restriction, objection, portability and withdrawal of consent. You may complain to your local data protection authority. Legitimate interests must be balanced against your rights and reasonable expectations; objections to direct marketing should be respected.
Naming our Chinese operator does not create an EU or UK establishment, local representative or data protection officer. If the business requires such a representative, officer or specific contact mechanism, it should be established and disclosed before the relevant processing. Swiss users retain applicable rights under Swiss data protection law.
14Additional information for California and other US states
Where CCPA / CPRA or another US state privacy law applies, you may request the categories and specific data collected, purposes and disclosures, correction or deletion, opt out of sale or sharing for cross-context behavioral advertising and, where applicable, limit sensitive-data use, opt out of certain profiling and appeal a decision. Requests and legally authorized agent requests can be sent to wangyizheng@abelien.cn.
This policy does not authorize selling personal information, sharing it for cross-context behavioral advertising or using sensitive information beyond necessary service purposes. Any future introduction requires prior notice, legally required opt-out mechanisms and respect for applicable Global Privacy Control signals. Additional request channels or appeals required by local law should be available. We do not unlawfully discriminate for exercising these rights.
15Children, updates and contact
The service is not directed to children under 14. Higher local age thresholds and guardian requirements take precedence. If ineligible child information is identified, processing should be restricted and the information reviewed and removed as required. Guardians may contact wangyizheng@abelien.cn.
This is version 1.0, published 2026-10-03. Material changes to the operator, purposes, categories, key recipients or rights should be clearly communicated, with renewed consent where legally required. An update does not retrospectively authorize previously unauthorized processing.