我们的隐私声明
隐私政策
生效日期:2025年1月1日
一、数据范围与性质
1. 数据类型说明
o 企业数据:客户提供的业务数据(如销售记录、设备日志、生产指标)
o 衍生数据:通过BI/AI工具生成的统计模型、趋势分析报告、特征向量
o 技术数据:系统运行日志(无用户标识的访问量、API调用频次)
2. 数据承诺
o 所有处理数据均不含个人身份信息(PII),且已通过以下技术处理:
✓ 聚合脱敏:原始数据经分组统计后删除个体标识
✓ 差分隐私:AI训练数据添加噪声防止逆向工程
✓ 数据合成:开发测试使用模拟生成的虚拟数据集
二、数据处理全流程控制
| 阶段 |
控制措施 |
| 数据接入 |
自动过滤敏感字段(如身份证/银行卡号),触发异常时立即中断并告警 |
| BI分析 |
报表系统强制行级权限控制(RLS),不同客户仅见自身数据 |
| AI开发 |
训练数据经k-匿名化处理(每组数据≥20条记录),模型发布前移除中间特征存储 |
| 数据共享 |
第三方需签署《非个人数据使用协议》,禁止用于法律禁止领域(如舆情监控) |
三、安全技术保障
1. 基础设施
o 存储加密:AWS S3服务器端加密(SSE-S3)+ 客户端加密(CSE)双重保护
o 传输安全:全链路TLS 1.3加密,VPN接入企业内网
2. 开发规范
o BI看板:所有查询结果自动模糊化(如±5%随机扰动)
o AI工具:模型推理API部署反爬机制(每分钟≤100次调用)
四、用户权利与透明度
尽管不涉及个人数据,我们仍提供:
• 数据知情权:通过[客户门户]实时查看自身数据使用情况
• 控制权:可随时导出业务数据或要求删除(需保留法律要求的备份副本)
• 异议权:对分析结论有异议时可申请人工复核
五、合规承诺
1. 国际标准
o 符合ISO 27001:2022对非个人数据的控制要求
o AI伦理遵循《欧盟AI法案》高风险系统豁免条款(Article 3.2)
2. 行业规范
o 制造业:满足IEC 62443工业数据保护标准
o 金融业:输出报告符合巴塞尔协议III数据治理规则
六、联系我们
数据安全委员会:rafezhu@aicool-tech.com
紧急事件响应:7×24小时电话 +86 021 61036757
政策执行说明
1. 所有员工入职时签署《非个人数据保密协议》
2. 每年委托第三方审计(如DNV)验证数据匿名化有效性
3. 本政策与客户合同冲突时,以合同条款为准
Our Privacy Statement
Privacy Policy
Effective Date: January 1, 2025
1. Data Scope and Nature
1.1 Data Type Description
o Enterprise Data: Business data provided by clients (e.g., sales records, equipment logs, production metrics)
o Derived Data: Statistical models, trend analysis reports, feature vectors generated through BI/AI tools
o Technical Data: System operation logs (access volume without user identification, API call frequency)
1.2 Data Commitment
o All processed data excludes personally identifiable information (PII) and has undergone the following technical treatments:
✓ Aggregate Anonymization: Original data grouped statistically with individual identifiers removed
✓ Differential Privacy: AI training data with added noise to prevent reverse engineering
✓ Data Synthesis: Development and testing use simulated virtual datasets
2. End-to-End Data Processing Controls
| Phase |
Control Measures |
| Data Ingestion |
Automatic filtering of sensitive fields (e.g., ID/bank card numbers), immediate interruption and alert upon exception triggers |
| BI Analysis |
Enforced row-level security (RLS) in reporting systems, each client only sees their own data |
| AI Development |
Training data undergoes k-anonymization (≥20 records per group), intermediate feature storage removed before model release |
| Data Sharing |
Third parties must sign "Non-Personal Data Usage Agreement", prohibited from use in legally restricted areas (e.g., public opinion monitoring) |
3. Security Technical Safeguards
3.1 Infrastructure
o Storage Encryption: AWS S3 server-side encryption (SSE-S3) + client-side encryption (CSE) dual protection
o Transmission Security: End-to-end TLS 1.3 encryption, VPN access for enterprise intranet
3.2 Development Standards
o BI Dashboards: All query results automatically obfuscated (e.g., ±5% random perturbation)
o AI Tools: Model inference APIs deploy anti-crawling mechanisms (≤100 calls per minute)
4. User Rights and Transparency
Although not involving personal data, we still provide:
• Data Right to Know: Real-time viewing of personal data usage through [Customer Portal]
• Control Right: Export business data or request deletion at any time (legal backup copies retained as required)
• Right to Object: Request manual review for disputed analysis conclusions
5. Compliance Commitments
5.1 International Standards
o Complies with ISO 27001:2022 requirements for non-personal data control
o AI ethics follow "EU AI Act" high-risk system exemption clauses (Article 3.2)
5.2 Industry Standards
o Manufacturing: Meets IEC 62443 industrial data protection standards
o Finance: Output reports comply with Basel III data governance rules
6. Contact Us
Data Security Committee: rafezhu@aicool-tech.com
Emergency Response: 24/7 hotline +86 021 61036757
Policy Implementation Notes
1. All employees sign "Non-Personal Data Confidentiality Agreement" upon hiring
2. Annual third-party audits (e.g., DNV) to verify data anonymization effectiveness
3. In case of conflict with client contracts, contract terms prevail