SenyanBiz (operated by Senyan Business HK Co., Limited, hereinafter referred to as "we," "our," or "us") recognizes the importance of personal information and is committed to protecting your personal information in accordance with applicable laws. This Privacy Policy explains how we collect, use, store, share, and protect your information.
Historical Versions: To review historical versions, please contact us at support@senyanbiz.com.
When registering, you must provide: phone number, company name, industry, and brand profile. This is used for account creation, identity verification, customer service, and billing.
When paying via bank transfer, we record the transfer amount, transfer reference number, and bank account information for payment and refund processing. We do not directly collect your bank card numbers.
Conversation instructions you provide to AI Employees, uploaded files (documents, images, audio/video, etc.), form submissions, and company profile settings, used to respond to your requests and provide AI Employee services.
Answers, proposals, work reports, design drafts, code, and other content automatically generated by AI Employees based on your inputs, as well as your feedback on outputs (thumbs up/down, revision comments).
AI content labeling: to comply with labeling requirements for AI-generated content and to support content provenance and anti-resale tracing, documents, reports, and other AI-generated content exported from the platform may contain an invisible source identifier (invisible fingerprint). This identifier records tenant-origin information, does not alter the content itself, and does not affect your normal viewing or use.
Including login records, feature clicks, page browsing, session duration, interaction history, IP address, browser type, and device identifiers. Used for security protection, system performance analysis, and service optimization.
Contact information, problem descriptions, and other information you provide when contacting customer support or submitting feedback.
Text, files, images, and other message content you send through the platform's instant messaging (IM) feature. Messages are stored with encryption on the server side, with the ability to edit or recall within 5 minutes of sending. Recalled messages will have their content cleared.
Data read from third-party services (such as Feishu, WeCom, GitHub, etc.) within the scope of your authorization when you grant the platform access through Connector features. Connectors support two authorization modes: shared (tenant-level) and personal (user-level overlay).
When you enable the BYOLLM (Bring Your Own LLM) feature and configure third-party API keys, your conversation instructions and context will be sent directly to your specified model provider, bypassing the platform's default model provider. The platform itself does not store or log the content of data sent to third-party model providers (see Section 4.1 for details).
When you connect to external tools via the MCP protocol or install third-party Skills, such tools or plugins may collect and process your data according to their own data policies. This platform assumes no liability for the data processing practices of third-party tools and plugins.
When you participate in referral sharing activities, the platform may collect uploaded share screenshots, sharing platform information, and sharing timestamps to verify the sharing activity and activate relevant benefits.
To safeguard account and asset security and to prevent theft and abuse, we collect device and security information, including: device unique identifier (Device ID), device model and operating system, IP address, User-Agent, browser type, login/registration timestamps, and activation records arising from activating the desktop client. This information is used for device management, identity verification, and anti-theft and anomaly detection (e.g., identifying bulk registration, multi-device/shared-device usage, and unauthorized access). Processing of this information is based on our legitimate interests.
We solemnly commit: Any Customer Inputs (instructions, uploaded files) and AI-generated Outputs you provide during use of the platform will not be used to train, fine-tune, or improve our underlying large language models or any other machine learning models.
Your data is used solely to provide you with the agreed AI Employee services. Upon service termination, we will delete or anonymize data in accordance with this policy.
We may share necessary information with the following categories of third parties to deliver our services:
We have entered into Data Processing Agreements (DPAs) with the above providers, ensuring they:
(1) Will not use your data for their own model training;
(2) Implement data protection measures no less stringent than the standards in this policy;
(3) Process data only within the scope necessary to provide the agreed services to you.
When the provider list is updated, we will notify you at least 7 calendar days in advance through platform announcements and update this policy accordingly. Material changes (such as adding providers involving cross-border data transfers) will additionally be notified via in-app message or email.
Except as stated above, we do not sell, trade, or rent your personal information to any third party.
We may disclose your information when required by laws, regulations, judicial orders, government demands, or to protect our legitimate rights and interests or those of the public.
In the event of a merger, acquisition, or asset sale, personal information may be transferred as an asset. We will require the transferee to remain bound by this policy.
We use a local-first storage model by default: business data (conversations, workspace files, boards & project data, connector credentials) is stored physically on your own computer (local encrypted store). Your account identity, real-time relay, and cloud services run on servers located in Singapore. Note: storage location depends on connection state — ①Desktop paired: your business data stays only on your computer (and in the client-encrypted Cloud Backup if you enable it); ②Unpaired / mobile or web only: related conversations, files, and boards are stored on our platform servers with server-side encryption so they remain accessible; once you install the desktop app and complete pairing, this data automatically converges to your computer and the cloud copy is removed per our cleanup mechanism (still being refined). Business data triggered via channel webhooks (e.g. WeChat/Feishu) is stored in the cloud by the channel itself.
With the optional paid Cloud Backup, your business data is client-side encrypted and backed up to the cloud, enabling recovery from a damaged or lost computer, multi-device sync, and cross-device retrieval. With client-side encryption, the cloud holds only an encrypted copy and cannot read your plaintext.
We employ AES-256 encrypted transmission (HTTPS/TLS 1.3), encryption at rest, role-based access control (RBAC), and regular security audits to protect data security.
Because account identity and certain processing are handled by us or by third parties, the following may involve cross-border transfers or sharing with third parties:
When your instructions are processed via third-party AI model API providers, data may be transferred to the servers of those providers (see Section 4.1 of this policy for details).
We will take measures in accordance with applicable laws — including the Personal Data (Privacy) Ordinance (PDPO) of the Hong Kong Special Administrative Region (Cap. 486) — including entering into standard contractual clauses and promoting security assessments where required, to ensure your data receives an adequate level of protection when transferred and stored overseas. We ensure that transfers of personal data outside Hong Kong comply with Section 33 of the PDPO and the data protection principles set out in the PDPO.
Current recipients that may be involved in cross-border transfers:
If you have questions about cross-border transfers, please contact us for more information.
Under applicable personal information protection laws, you (and individuals such as employees of the organization you represent) may have the following rights:
You may exercise the above rights through the in-platform feedback channel or by emailing support@senyanbiz.com. We will respond within the time period required by law. We may need to verify your identity for security purposes.
If your account has been subjected to measures such as a ban due to anomaly detection and you believe the decision was erroneous, you may appeal through the above channels, and we will review the matter within a reasonable period and inform you of the outcome.
As an enterprise account administrator, you are responsible for providing this Privacy Policy to data subjects such as your employees and informing them of how to exercise their rights.
We will retain your personal information only for the period necessary to fulfill the purposes described in this policy and as required by applicable laws and regulations. Generally:
We implement the following comprehensive administrative, physical, and technical security measures to protect your personal information:
However, please note that no security measures are absolutely perfect; we continuously improve.
This platform is intended for enterprise users and is not directed at minors. We do not knowingly collect personal information from minors under 14 years of age. If you discover that we have inadvertently collected such information, please contact us immediately for deletion.
We may update this Privacy Policy from time to time. The update rules are as follows:
You may review historical versions: Visit Platform [Settings - Privacy Policy History] to view all prior versions and change summaries.
Continued use of the platform constitutes your agreement to be bound by the updated policy. If you do not agree to the changes, please discontinue use of the platform and contact us to handle your account.
If you have any questions, comments, or complaints about this Privacy Policy, or wish to exercise your personal information rights, please contact us through the following channels:
Responsible Entity:
We will respond to your requests within 15 business days.
If you are located in Hong Kong and are not satisfied with how we handle your personal data, you may lodge a complaint with the Privacy Commissioner for Personal Data (PCPD) of Hong Kong in accordance with the PDPO.
| Version | Effective Date | Change Summary |
|---|---|---|
| v1.0 | July 15, 2026 | Initial release |
| v1.1 | August 1, 2026 | Added new data collection types (IM Chat, Connector Integration, BYOLLM, MCP External Tools/Plugins, Referral Sharing); updated LLM provider list |
| v1.2 | August 3, 2026 | Added device and security information collection, anti-theft and anomaly detection and handling, and ban appeal procedures |
| v1.3 | August 15, 2026 | Added Hong Kong PDPO (Cap. 486) compliance references for cross-border transfers and complaints (PCPD); clarified Senyan Business HK Co., Limited as the data controller for Hong Kong users |
| v1.4 | August 20, 2026 | Unified the policy under Senyan Business HK Co., Limited as the sole responsible entity; removed the Chinese Mainland entity and the PIPL reference, keeping Hong Kong PDPO compliance for cross-border transfers |