Privacy Policy
隐私政策
Last Updated / 最后更新日期: 2026.05.02
Effective Date / 生效日期: 2026.05.02
Important Notice / 重要提示
Please read this Privacy Policy carefully to understand how Flux Art collects, uses, shares, and protects your personal data.
请仔细阅读本隐私政策,以了解 Flux Art 如何收集、使用、共享和保护您的个人资料。
Privacy at a Glance
The table below is a plain-language summary of the most-asked questions about how we handle your data. It does not replace the full Privacy Policy below — the detailed sections govern in case of any conflict.
- What data do we collect? Account information, billing data, your prompts and generated outputs, usage and device data, and a small set of cookies. See Section 2.
- Do we use your content to train AI models? No. We do not train our own foundational AI models, and we do not use your prompts, uploaded reference materials, or generated Outputs to train, fine-tune, or otherwise develop machine-learning models. See Section 5.
- Do we sell your personal data? No. See Section 7.
- Who can access your data? Our authorized engineering and support staff, plus a small set of vetted sub-processors (cloud hosting, payment processing, third-party AI model providers, email delivery, analytics). See Section 8.
- How long do we keep your data? Account info: while active + up to 24 months. Billing records: at least 7 years for tax/AML. User content: until you delete it. Logs: up to 12 months. See Section 10.
- What rights do you have? Access, correct, delete, export, object, withdraw consent, and opt out of "sale/sharing" (including via the Global Privacy Control signal). See Section 14.
- How do you contact us? [email protected] — see Section 20.
Flux Art is operated by MORNING STAR INDUSTRY LIMITED, a company incorporated in Hong Kong ("Flux Art," "Company," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, store, and otherwise process personal data when you access or use https://flux-art.ai and any related websites, applications, software, APIs, tools, and services we provide (collectively, the "Services").
This Privacy Policy should be read together with our Terms of Use and any other notices we may provide to you at the time we collect your data.
Scope of This Privacy Policy
This Privacy Policy applies to personal data we collect when you:
- visit our website;
- create or use a Flux Art account;
- use our web, mobile, desktop, or API-based Services;
- contact us for support, business inquiries, or legal requests; or
- otherwise interact with us in connection with the Services.
This Privacy Policy does not apply to third-party websites, products, or services that are not operated by us, even if they are linked to or integrated with our Services.
Personal Data We Collect
We may collect the following categories of personal data, depending on how you interact with the Services:
2.1 Information You Provide to Us
- Account Information: such as your name, email address, username, password, profile details, billing country, and account preferences.
- Payment and Transaction Information: such as subscription plan, purchase history, billing status, invoice details, and limited payment-related information provided by our payment processors. We do not typically store full payment card numbers.
- User Content: such as prompts, text, images, files, edits, instructions, and other content you upload, submit, generate, or request through the Services.
- Communications: such as the contents of messages, support requests, feedback, survey responses, and correspondence you send to us.
2.2 Information We Collect Automatically
- Usage Information: such as the features you use, pages you visit, actions you take, timestamps, referring URLs, and interactions with the Services.
- Device and Technical Information: such as IP address, browser type, device type, operating system, app version, language settings, crash reports, and diagnostic logs.
- Cookie and Similar Technology Data: such as cookie identifiers, advertising identifiers, and information collected through pixels, local storage, SDKs, and similar technologies.
2.3 Information We Receive from Third Parties
- Login or Account Providers: if you register or sign in through a third-party login provider.
- Payment Processors: limited transaction and payment status information.
- Analytics, Advertising, and Fraud Prevention Partners: information used to help us measure traffic, prevent abuse, and improve our Services.
- Referral, Affiliate, or Marketing Partners: where you arrive through a referral or campaign.
How We Use Personal Data
We may use personal data for the following purposes:
- to provide, operate, maintain, and improve the Services;
- to create and manage your account;
- to process purchases, subscriptions, renewals, refunds, and billing administration;
- to provide AI-generated outputs and requested features;
- to authenticate users and secure the Services;
- to detect, prevent, investigate, and address fraud, abuse, policy violations, illegal activity, and security incidents;
- to respond to support requests, feedback, and inquiries;
- to send service-related notices, technical updates, security alerts, and legal communications;
- to send marketing communications where permitted by law and subject to your preferences;
- to conduct analytics, debugging, quality assurance, product development, and service optimization;
- to comply with legal obligations and enforce our agreements; and
- to establish, exercise, or defend legal claims.
Legal Bases for Processing
If you are located in a jurisdiction that requires a legal basis for processing personal data, including the European Economic Area, the United Kingdom, or Switzerland, we generally rely on one or more of the following legal bases:
- Performance of a contract: where processing is necessary to provide the Services you request.
- Legitimate interests: where processing is necessary for our legitimate business interests, such as securing, operating, and improving the Services, provided that such interests are not overridden by your rights.
- Consent: where required by law, such as for certain cookies or direct marketing activities.
- Legal obligation: where processing is necessary to comply with applicable law, regulation, court order, or lawful request.
How We Use User Content (No Model Training)
We process prompts, images, files, and other User Content to provide the functionality you request, including generating, editing, transforming, storing, and displaying outputs.
We may also use User Content:
- to maintain and improve service quality, safety, and reliability;
- to detect abuse, fraud, or policy violations; and
- to comply with legal obligations.
5.1 No Use for Model Training. We do not train our own foundational AI models. We do not use your prompts, uploaded reference materials, or generated Outputs to train, fine-tune, or otherwise develop machine-learning models. This commitment applies to all individual user accounts; if we ever introduce a feature or program that permits opt-in contribution of data for model improvement, it will be presented separately with clear, granular consent and will be off by default.
5.2 Third-Party Model Providers. The Services rely on third-party AI model providers (listed in Section 8) to perform generation, moderation, and related tasks. These providers process your Inputs and Outputs to deliver the requested results to us. Some providers may, under their own policies, use submitted content for their own training or service-improvement purposes; where commercially available, we configure our integrations to disable third-party training on your content and to honor "do not train" or "zero data retention" options offered by the relevant provider. Each provider's data-handling practices are governed by its own policies.
5.3 Safety, Moderation, and Legal Holds. Where required by law or by our content-moderation obligations, we may retain copies of specific User Content (for example, content matched to known-bad hashes, or content subject to a preserve-evidence request from law enforcement) beyond normal retention windows. Such retention is strictly limited to the legitimate purpose and is held under restricted access.
Cookies and Similar Technologies
We use cookies and similar technologies to operate and improve the Services. These may include:
- Essential Cookies: necessary for authentication, security, network management, and core functionality.
- Preference Cookies: used to remember settings such as language, login state, and interface preferences.
- Analytics Cookies: used to understand traffic, usage patterns, feature performance, and product quality.
- Advertising Cookies: where permitted, used to measure campaigns and show more relevant promotions on third-party platforms.
- Affiliate or Referral Cookies: used to attribute referrals and partner traffic.
You can manage cookies through your browser settings and, where required by law, through our cookie banner or consent tools. Please note that disabling certain cookies may affect the functionality of the Services.
How We Share Personal Data
We may share personal data with the following categories of recipients:
- Service Providers: including hosting, cloud infrastructure, payment processing, analytics, customer support, security, email delivery, and other vendors who process data on our behalf under contractual safeguards (see Section 8 for the categorized list).
- AI and Technology Providers: where necessary to provide generation, processing, moderation, storage, or related technical functions.
- Professional Advisers: such as lawyers, auditors, insurers, and consultants, where reasonably necessary.
- Corporate Transaction Participants: in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar transaction.
- Authorities and Law Enforcement: where required by law or where necessary to protect rights, safety, property, users, or the public.
- Other Parties at Your Direction: where you choose to connect third-party services or request that we share data.
We do not sell personal data for monetary consideration. If applicable law treats certain disclosures for advertising or analytics purposes as a "sale" or "sharing," you may have the right to opt out as described in Section 14 ("Your Privacy Rights").
Sub-processors
We engage trusted third-party sub-processors to help us operate the Services. We require our sub-processors, by contract, to provide at least the same level of data protection that we commit to under this Privacy Policy, to process personal data only on our documented instructions, and to assist us in responding to user-rights requests and security incidents.
The current categories of sub-processors include:
- Cloud Infrastructure & Storage: e.g., Cloudflare, AWS, Google Cloud Storage, and equivalent providers used for compute, content delivery, DNS, and object storage. Data is stored in the region appropriate to the user's location and our service architecture.
- Third-Party AI Model Providers: a curated set of leading AI model and inference providers (which may include providers headquartered in the United States, Europe, and Asia) used solely to perform the text-to-image, image-editing, video-generation, and moderation tasks that you request. The current list of specific providers, their function, and the region in which they process data is available on request by emailing [email protected].
- Payment Processing: our authorized payment processors used to securely accept payments and process refunds and chargebacks.
- Email Delivery: transactional email providers (such as Resend, Postmark, or similar) used to deliver account, security, and service emails.
- Analytics & Observability: privacy-respecting analytics, error monitoring, and product-telemetry providers.
- Customer Support: ticketing or live-chat tools used by our support team to respond to your requests.
An up-to-date list of specific sub-processor entities, along with their function and the region in which they process data, is available on request by emailing [email protected]. We will provide reasonable notice of material changes to our sub-processor roster.
International Data Transfers
We process personal data in Hong Kong, where Flux Art is established, and may transfer data to service providers and sub-processors operating in the United States, the European Economic Area, the United Kingdom, Singapore, and other regions where our infrastructure or sub-processors are located.
Data Localization by User Region. For users located in the EEA, the United Kingdom, Switzerland, the United States, and other jurisdictions outside the People's Republic of China, personal data is processed in Hong Kong, the United States, Singapore, the European Economic Area, and the United Kingdom; we do not route the personal data of these users to processing facilities located within the People's Republic of China. For users located within the People's Republic of China, personal data may additionally be processed within the People's Republic of China to comply with applicable local data-localization laws.
Because Hong Kong has not received an "adequacy decision" from the European Commission, when we transfer personal data of EEA, UK, or Swiss residents to Hong Kong or to other non-adequate jurisdictions, we rely on the following lawful transfer mechanisms:
- the European Commission's Standard Contractual Clauses (SCCs) (Module 1, 2, or 3 as applicable) for transfers out of the EEA;
- the UK International Data Transfer Addendum (IDTA) or the UK Addendum to the EU SCCs, for transfers out of the United Kingdom;
- the Swiss FADP-compliant variant of the SCCs, for transfers out of Switzerland;
- where required, supplementary technical and organizational measures (such as encryption in transit and at rest, access controls, and pseudonymization) identified through a Transfer Impact Assessment; and
- other lawful transfer mechanisms permitted by applicable law (such as your explicit consent, or transfers necessary for the performance of a contract with you).
You may request a copy of the relevant transfer mechanism, with commercial and confidential information redacted where appropriate, by contacting [email protected].
Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention periods include:
- Account Information: retained while your account is active and for up to 24 months after account closure to handle disputes, fraud investigation, legal claims, and tax/accounting obligations.
- Billing and Transaction Records: retained for at least 7 years to comply with applicable tax, accounting, and anti-money-laundering laws (this is generally the longest mandatory retention period in relevant jurisdictions including Hong Kong, the EU, the U.S., and the U.K.).
- User Content (prompts, reference materials, generated Outputs): retained for as long as needed to provide the Services. Generated images and videos remain accessible in your account until you delete them or your account is closed; thereafter, residual copies are deleted from active systems within 30 days, subject to ordinary backup-rotation windows of up to 90 days.
- Support Communications: retained for up to 36 months after the last interaction.
- Usage Logs and Security Logs: retained for up to 12 months, unless longer retention is required for security investigation, fraud prevention, or legal compliance.
- Content Flagged Under Section 5.3 (Safety / Legal Holds): retained for the duration of the relevant legal hold or moderation obligation.
When personal data is no longer needed, we will delete, anonymize, or securely dispose of it, unless retention is required by law.
Data Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. These measures may include access controls, encryption in transit where appropriate, network protections, logging, and role-based restrictions.
However, no method of transmission over the Internet or method of storage is completely secure. We therefore cannot guarantee absolute security.
Data Breach Notification
We operate an incident-response process to detect, investigate, contain, and remediate personal-data security incidents.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where required by law, the relevant supervisory authorities, in accordance with applicable legal obligations (including GDPR Articles 33 and 34, the UK GDPR equivalents, and any other applicable breach-notification laws). Notifications will be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where notification to all affected individuals would involve disproportionate effort, we may provide a public communication or equivalent measure by which affected individuals are informed in an equally effective manner, as permitted by applicable law.
Children's Privacy
The Services are intended for users who are 18 years of age or older, consistent with Section 1 of our Terms of Use. We do not knowingly collect personal data from individuals under 18.
If you believe that a person under 18 has provided personal data to us, please contact us at [email protected] so that we can promptly delete the data and terminate the relevant account.
For users in jurisdictions where the digital age of consent is lower than 18 (for example, certain EU member states under GDPR Article 8), our 18+ age requirement still applies as a contractual matter; in addition, where local law sets a separate minimum age of digital consent that is lower, parental consent requirements under that local law apply in addition to our age-gating measures.
Your Privacy Rights
Depending on where you live, you may have certain rights regarding your personal data, subject to applicable law and any permitted exceptions. These rights may include:
- the right to access personal data we hold about you;
- the right to correct inaccurate or incomplete personal data;
- the right to request deletion of personal data;
- the right to object to or restrict certain processing;
- the right to withdraw consent where processing is based on consent;
- the right to data portability, where applicable;
- the right to opt out of certain marketing communications; and
- the right not to be discriminated against for exercising applicable privacy rights.
14.1 Response Timelines. We will respond to verified privacy-rights requests within 30 days where required by applicable law (such as GDPR Article 12). Where the request is complex or we have received a high volume of requests, we may extend this period by up to 60 additional days and will notify you of the extension and the reasons for it. For California residents, we will respond within 45 days as required by the CCPA, with one possible 45-day extension.
14.2 Hong Kong. If the Personal Data (Privacy) Ordinance (Cap. 486) applies, you may have the right to request access to and correction of your personal data. We may need to verify your identity before responding, and we may charge a reasonable fee where permitted by law for complying with a data access request.
14.3 EEA / UK / Switzerland. If applicable, you may also have rights under the GDPR, the UK GDPR, or equivalent laws, including rights to restriction, portability, and objection. You have the right to lodge a complaint with your local supervisory authority — for example, the Information Commissioner's Office (ICO) in the UK, the Irish Data Protection Commission, or the supervisory authority in the EU member state of your residence.
14.4 California / Global Privacy Control. If the California Consumer Privacy Act, as amended by the CPRA, applies to your data, you may have the right to know, access, correct, delete, and opt out of certain sales or sharing of personal information, subject to statutory exceptions. We recognize and honor the Global Privacy Control (GPC) signal as a valid request to opt out of any "sale" or "sharing" of personal information under California law. When we detect a GPC signal from your browser, we will treat it as such an opt-out request for the browser session and, where it can be linked to a known user account, for that account.
To exercise any applicable rights, please contact us using the details in Section 20 ("Contact Us"). We may need to verify your identity and authority before fulfilling your request.
Marketing Communications
We may send you marketing emails or similar communications where permitted by law. You can unsubscribe at any time by using the unsubscribe link in the message or by contacting us.
Even if you opt out of marketing communications, we may still send you non-promotional communications relating to your account, transactions, security, legal notices, or service updates.
Third-Party Links and Services
The Services may contain links to third-party websites, applications, plug-ins, or services. We are not responsible for the privacy practices of those third parties, and this Privacy Policy does not apply to them. We encourage you to review their privacy policies separately.
Automated Processing
We may use automated systems to operate and secure the Services, including for content generation, moderation, fraud detection, abuse prevention, personalization, and service optimization.
We do not use solely automated decision-making that produces legal or similarly significant effects on individuals unless permitted by applicable law and accompanied by any required safeguards.
Data Protection Contact
While we are not currently legally required to appoint a Data Protection Officer under GDPR Article 37, our Data Protection Contact handles all data-protection inquiries, user-rights requests, and breach-notification matters. The Data Protection Contact can be reached at [email protected].
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make material changes, we will update the "Last Updated" date and provide additional notice where required by law.
Your continued use of the Services after the effective date of the updated Privacy Policy constitutes your acknowledgment of the revised Privacy Policy, to the extent permitted by law.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of personal data, please contact us at:
Flux Art
MORNING STAR INDUSTRY LIMITED
Website: https://flux-art.ai
Support Email: [email protected]
Privacy / Legal Email: [email protected]
Registered Office: RM 19, UNIT C1, 6/F, KAISER ESTATE PHASE 1, 41 MAN YUE STREET, HUNG HOM HK
隐私要点速览
下表为您最关心的核心问题的通俗摘要。本摘要不替代下方完整隐私政策,如有不一致,以下方详细条款为准。
- 你们会收集哪些资料? 账户资料、账单资料、您的提示词及生成结果、使用与设备资料,以及少量 Cookie。详见第 2 条。
- 会用我的内容训练 AI 模型吗? 不会。我们不训练自有的基础 AI 模型,也不会使用您的提示词、上传的参考素材或生成的输出来训练、微调或以其他方式开发机器学习模型。详见第 5 条。
- 会"出售"我的个人资料吗? 不会。详见第 7 条。
- 谁能访问我的数据? 我们经授权的工程与客服团队,以及少量经审慎评估的子处理者(云托管、支付处理、第三方 AI 模型供应商、邮件发送、数据分析等)。详见第 8 条。
- 资料会保留多久? 账户资料:账户存续 + 至多 24 个月;账单记录:因税务/反洗钱需要至少 7 年;用户内容:在您删除前一直保留;日志:至多 12 个月。详见第 10 条。
- 我有哪些权利? 访问、更正、删除、导出、反对、撤回同意,以及选择退出"出售/共享"(包括通过 Global Privacy Control 信号)。详见第 14 条。
- 如何联系我们? [email protected] —— 详见第 20 条。
Flux Art 由 MORNING STAR INDUSTRY LIMITED 运营(以下简称"Flux Art"、"本公司"、"我们")。本隐私政策说明当您访问或使用 https://flux-art.ai 以及我们提供的任何相关网站、应用程序、软件、API、工具和服务(以下合称"本服务")时,我们如何收集、使用、披露、存储及以其他方式处理您的个人资料。
本隐私政策应与我们的《服务条款》及我们在收集您资料时向您提供的其他通知一并阅读。
本隐私政策的适用范围
本隐私政策适用于我们在以下情形中收集的个人资料:
- 您访问我们的网站;
- 您创建或使用 Flux Art 账户;
- 您使用我们的网页端、移动端、桌面端或 API 服务;
- 您就客服、商务合作或法律事务与我们联系;或
- 您以其他方式就本服务与我们发生互动。
本隐私政策不适用于任何非由我们运营的第三方网站、产品或服务,即使其与本服务存在链接或集成关系。
我们收集的个人资料
根据您与本服务的互动方式,我们可能收集以下类别的个人资料:
2.1 您主动提供给我们的资料
- 账户资料:例如您的姓名、电子邮箱、用户名、密码、个人资料信息、账单国家/地区及账户偏好设置。
- 支付与交易资料:例如订阅方案、购买记录、账单状态、发票信息,以及由支付处理机构向我们提供的有限支付相关信息。通常情况下,我们不会存储完整的银行卡号。
- 用户内容:例如您通过本服务上传、提交、生成或请求处理的提示词、文本、图像、文件、编辑内容、指令及其他内容。
- 沟通资料:例如您向我们发送的消息内容、客服请求、反馈、问卷回复及其他往来信息。
2.2 我们自动收集的资料
- 使用资料:例如您使用的功能、访问的页面、执行的操作、时间戳、来源网址以及您与本服务的交互情况。
- 设备与技术资料:例如 IP 地址、浏览器类型、设备类型、操作系统、应用版本、语言设置、崩溃报告及诊断日志。
- Cookie 及类似技术资料:例如 Cookie 标识符、广告标识符,以及通过像素、本地存储、SDK 和类似技术收集的信息。
2.3 我们从第三方获得的资料
- 登录或账户服务提供方:如您通过第三方登录服务注册或登录;
- 支付处理机构:向我们提供有限的交易和支付状态信息;
- 分析、广告及反欺诈合作伙伴:帮助我们统计流量、防止滥用并改进服务;
- 推荐、联盟或营销合作伙伴:当您通过推荐链接或营销活动进入本服务时。
我们如何使用个人资料
我们可能将个人资料用于以下目的:
- 提供、运营、维护和改进本服务;
- 创建和管理您的账户;
- 处理购买、订阅、续费、退款和账务管理;
- 提供 AI 生成结果及您请求的功能;
- 验证用户身份并保障服务安全;
- 识别、防止、调查和处理欺诈、滥用、政策违规、违法行为及安全事件;
- 响应客服请求、反馈和咨询;
- 发送与服务相关的通知、技术更新、安全提醒及法律通知;
- 在法律允许且符合您的偏好设置的前提下发送营销信息;
- 进行分析、排障、质量保证、产品开发及服务优化;
- 履行法律义务并执行我们的协议;以及
- 建立、行使或抗辩法律主张。
处理个人资料的法律依据
如果您位于要求处理个人资料必须有法律依据的司法管辖区,包括欧洲经济区、英国或瑞士,我们通常会基于以下一项或多项法律依据处理您的个人资料:
- 履行合同:为向您提供所请求的服务而必须进行的处理;
- 合法利益:为保障、运营和改进本服务等我们的正当商业利益所必需的处理,前提是该等利益不凌驾于您的权利和利益之上;
- 同意:在法律要求的情况下,例如某些 Cookie 或直销活动;
- 法定义务:为遵守适用法律、法规、法院命令或合法要求所必需的处理。
我们如何使用用户内容(不用于训练模型)
我们会处理您的提示词、图像、文件及其他用户内容,以提供您请求的功能,包括生成、编辑、转换、存储和展示输出结果。
我们也可能将用户内容用于:
- 维护和提升服务质量、安全性和可靠性;
- 识别滥用、欺诈或政策违规行为;以及
- 履行法律义务。
5.1 不用于模型训练。我们不训练自有的基础 AI 模型。我们不会使用您的提示词、上传的参考素材或生成的输出来训练、微调或以其他方式开发机器学习模型。该承诺适用于所有个人用户账户。如未来我们引入允许用户主动授权贡献数据以改进模型的功能或计划,将以单独清晰的颗粒化同意流程呈现,并默认关闭。
5.2 第三方模型供应商。本服务依赖第三方 AI 模型供应商(详见第 8 条)执行生成、审核及相关任务。该等供应商处理您的输入和输出,以向我们交付您所请求的结果。部分供应商可能依据其自身政策将提交内容用于其自身的训练或服务改进等用途;在商业可行的情况下,我们将在与第三方供应商的对接中关闭对您内容的训练用途,并遵循其提供的"do not train"或"零数据留存(zero data retention)"选项。每家供应商的数据处理实践受其自身政策约束。
5.3 安全、内容审核与法律留存。在法律或我们的内容审核义务要求的情况下,我们可能在常规留存窗口之外保留特定用户内容副本(例如,与已知违规哈希匹配的内容、或受执法机构证据保全请求约束的内容)。此类留存严格限于正当目的,并以受限访问的方式保存。
Cookie 及类似技术
我们使用 Cookie 及类似技术来运营和改进本服务,可能包括:
- 必要 Cookie:用于身份验证、安全、网络管理及核心功能;
- 偏好 Cookie:用于记住语言、登录状态和界面偏好等设置;
- 分析 Cookie:用于了解流量、使用模式、功能表现及产品质量;
- 广告 Cookie:在法律允许的情况下,用于衡量营销活动效果并在第三方平台上展示更相关的推广内容;
- 联盟或推荐 Cookie:用于归因推荐来源及合作伙伴流量。
您可以通过浏览器设置管理 Cookie,并在法律要求的情况下通过我们的 Cookie 横幅或同意工具进行选择。请注意,禁用某些 Cookie 可能影响本服务的功能。
我们如何共享个人资料
我们可能向以下类别的接收方共享个人资料:
- 服务提供商:包括托管、云基础设施、支付处理、数据分析、客户支持、安全、邮件投递及其他代表我们处理数据的供应商,并受合同保护义务约束(详细类目见第 8 条);
- AI 与技术提供商:在提供生成、处理、审核、存储或其他相关技术功能所必需的范围内;
- 专业顾问:如律师、审计师、保险机构及顾问,在合理必要范围内;
- 公司交易相关方:例如在合并、收购、融资、重组、资产出售或类似交易中;
- 政府机关与执法机构:在法律要求或为保护权利、安全、财产、用户或公众利益所必需的情况下;
- 您指示的其他方:例如您选择连接第三方服务或要求我们共享数据时。
我们不会为获取金钱对价而出售个人资料。如果适用法律将某些用于广告或分析目的的数据披露认定为"出售"或"共享",您可能有权按照下文第 14 条(您的隐私权利)所述进行选择退出。
子处理者
我们聘用受信任的第三方子处理者协助运营本服务。我们通过合同要求所有子处理者至少提供与本隐私政策相同水准的数据保护、仅按我们的书面指令处理个人资料,并在用户权利请求及安全事件响应方面给予协助。
现行子处理者类别包括:
- 云基础设施与存储:例如 Cloudflare、AWS、Google Cloud Storage 及同类供应商,用于计算、内容分发、DNS 和对象存储。数据按用户所在地区及我们的服务架构在适当的区域存储;
- 第三方 AI 模型供应商:经我们审慎评估的一组业界领先的 AI 模型与推理服务供应商(可能包括总部位于美国、欧洲及亚洲的供应商),仅用于执行您所请求的文生图、图像编辑、视频生成及内容审核任务。具体供应商名单(含功能用途与处理数据所在地区)可通过邮件 [email protected] 索取;
- 支付处理:我们授权的支付处理机构,用于安全收款及处理退款与拒付;
- 邮件发送:事务性邮件供应商(如 Resend、Postmark 或同类),用于发送账户、安全和服务邮件;
- 数据分析与可观测:注重隐私的分析、错误监控和产品遥测供应商;
- 客户支持:客服团队用于响应您请求的工单或在线聊天工具。
具体子处理者名单(含功能用途与处理数据所在地区)的最新版本可通过邮件 [email protected] 索取。我们将就子处理者名单的重大变更提前作出合理通知。
跨境传输
我们在 Flux Art 注册地——香港处理个人资料,并可能将数据传输至位于美国、欧洲经济区、英国、新加坡以及其他我们基础设施或子处理者所在地区的服务提供商和子处理者。
按用户地区划分的数据本地化。对于位于欧洲经济区、英国、瑞士、美国及其他中华人民共和国境外司法管辖区的用户,我们在香港、美国、新加坡、欧洲经济区及英国处理其个人资料;我们不会将该等用户的个人资料路由至位于中华人民共和国境内的处理设施。对于位于中华人民共和国境内的用户,为遵守当地适用的数据本地化法律,其个人资料可能会在中华人民共和国境内额外进行处理。
由于香港尚未获得欧盟委员会的"充分性认定(adequacy decision)",当我们将欧洲经济区、英国或瑞士居民的个人资料传输至香港或其他非充分性认定地区时,我们依据以下合法传输机制:
- 就来自欧洲经济区的传输,采用欧盟委员会的 标准合同条款(Standard Contractual Clauses, SCCs)(视情形适用第 1、2 或 3 模块);
- 就来自英国的传输,采用 UK International Data Transfer Addendum(IDTA) 或 UK Addendum to the EU SCCs;
- 就来自瑞士的传输,采用符合瑞士 FADP 的 SCC 变体;
- 在必要的情况下,结合通过 传输影响评估(Transfer Impact Assessment)识别的补充技术与组织措施(如传输中和静态加密、访问控制、假名化等);以及
- 适用法律允许的其他合法传输机制(例如您的明示同意,或为履行与您之间的合同所必需的传输等)。
您可通过邮件 [email protected] 索取相关传输机制副本(可适当对商业和保密信息进行脱敏处理)。
数据保留
除法律要求或允许更长保留期限外,我们仅在实现本隐私政策所述目的所合理必要的期限内保留个人资料。具体保留期限如下:
- 账户资料:在您的账户存续期间保留,并在账户关闭后至多 24 个月内继续保留,以处理争议、欺诈调查、法律主张及税务/会计义务;
- 账单与交易记录:至少保留 7 年,以遵守适用的税务、会计与反洗钱法律(这通常是香港、欧盟、美国和英国等相关辖区中最长的强制保留期限);
- 用户内容(提示词、参考素材、生成结果):在为您提供服务所需的期间内保留。生成的图像和视频在您账户中保持可访问,直至您删除或账户关闭;账户关闭后,残留副本将在 30 天内从在线系统中删除,常规备份滚动窗口可至 90 天;
- 客服沟通记录:自最后一次互动起最多保留 36 个月;
- 使用日志与安全日志:最多保留 12 个月,但如出于安全调查、反欺诈或法律合规需要,可保留更长时间;
- 依第 5.3 条标记的安全/法律留存内容:在相关法律留存或内容审核义务存续期间内保留。
当个人资料不再需要时,我们将删除、匿名化或以安全方式处置相关资料,但法律要求继续保留的除外。
数据安全
我们采取合理的管理、技术和物理安全措施,以保护个人资料免遭未经授权的访问、披露、篡改、丢失或毁坏。该等措施可能包括访问控制、适当情形下的传输加密、网络防护、日志记录及基于角色的权限限制。
但互联网传输或电子存储方式均无法保证绝对安全,因此我们无法保证个人资料的绝对安全。
数据泄露通知
我们建立有事件响应流程,用于发现、调查、遏制并修复涉及个人资料的安全事件。
如发生可能对您的权利和自由构成风险的个人资料泄露事件,我们将按适用法律义务(包括 GDPR 第 33 条及第 34 条、英国 GDPR 的对应规定及其他适用的泄露通知法律)通知受影响用户,并在法律要求的情况下通知相关监管机构。通知将在我们获悉泄露后不无故拖延地发出,并在可行情况下于 72 小时内完成。
如向所有受影响个人发出通知会涉及不成比例的努力,我们可能依适用法律以同等有效的方式发布公告或采取等同措施,以告知受影响个人。
儿童隐私
本服务面向年满 18 周岁的用户提供,与我们《服务条款》第 1 条保持一致。我们不会故意收集任何未满 18 周岁人士的个人资料。
如您认为有未满 18 周岁的人士向我们提供了个人资料,请通过 [email protected] 与我们联系,以便我们及时删除该等资料并终止相关账户。
在数字同意年龄低于 18 周岁的司法管辖区(例如部分欧盟成员国依据 GDPR 第 8 条的规定),我们仍以合同方式要求用户年满 18 周岁;此外,在当地法律规定的更低数字同意年龄项下所要求的家长同意义务,仍叠加适用于我们的年龄筛查措施。
您的隐私权利
根据您所在地及适用法律,您可能就您的个人资料享有一定权利,但该等权利可能受法定例外限制。这些权利可能包括:
- 访问我们持有的您的个人资料的权利;
- 更正不准确或不完整个人资料的权利;
- 请求删除个人资料的权利;
- 反对或限制某些处理活动的权利;
- 在基于同意处理时撤回同意的权利;
- 在适用情况下的数据可携权;
- 选择退出某些营销通信的权利;以及
- 因行使适用隐私权利而不受歧视待遇的权利。
14.1 响应时限。对经核实的隐私权利请求,我们将在适用法律要求的范围内(如 GDPR 第 12 条)于 30 天内回复。如请求复杂或我们收到的请求数量较多,我们可将该期限延长至多 60 天,并将延长事项及理由告知您。对加州居民的请求,我们将按 CCPA 要求在 45 天内回复,必要时可再延长 45 天。
14.2 香港。如《个人资料(私隐)条例》(香港法例第 486 章)适用于您的资料,您可能有权要求查阅及更正您的个人资料。我们在回应前可能需要核实您的身份,并可在法律允许范围内就数据查阅请求收取合理费用。
14.3 欧洲经济区 / 英国 / 瑞士。在适用情况下,您还可能享有 GDPR、英国 GDPR 或同等法律项下的限制处理、数据可携、反对处理等权利,并有权向您所在地的监管机构提出投诉——例如英国信息专员办公室(ICO)、爱尔兰数据保护委员会、或您居住地所在欧盟成员国的监管机构。
14.4 加州 / Global Privacy Control。如经修订后的《加州消费者隐私法案》(CCPA/CPRA)适用于您的资料,您可能享有知情、访问、更正、删除以及对某些个人信息"出售"或"共享"选择退出的权利,但受法定例外限制。我们尊重并履行 Global Privacy Control(GPC)信号,将其视为加州法律项下对"出售"或"共享"个人信息有效的选择退出请求。在检测到您浏览器发出的 GPC 信号时,我们将就当前浏览器会话据此处理;如该信号可与已知用户账户关联,亦将就该账户据此处理。
如您希望行使适用权利,请通过第 20 条(联系我们)所列方式与我们联系。我们在处理请求前,可能需要核实您的身份及授权情况。
营销通信
在法律允许的情况下,我们可能向您发送营销邮件或类似信息。您可随时通过信息中的退订链接或联系我们取消订阅。
即使您选择退出营销通信,我们仍可能向您发送与账户、交易、安全、法律通知或服务更新相关的非营销信息。
第三方链接与服务
本服务可能包含指向第三方网站、应用、插件或服务的链接。我们不对该等第三方的隐私做法负责,本隐私政策亦不适用于该等第三方。我们建议您另行查阅其隐私政策。
自动化处理
我们可能使用自动化系统来运营和保护本服务,包括用于内容生成、内容审核、欺诈检测、滥用防范、个性化及服务优化。
除非适用法律允许并已配备必要保障措施,否则我们不会仅基于自动化处理作出对个人产生法律效果或类似重大影响的决定。
数据保护联系人
目前我们并未依 GDPR 第 37 条被法律强制要求设立数据保护官(DPO),但我们设有数据保护联系人,负责处理所有数据保护咨询、用户权利请求与泄露通知事项。数据保护联系人邮箱:[email protected]。
本隐私政策的变更
我们可能不时更新本隐私政策,以反映我们的实践、技术、法律要求或业务运营的变化。如发生重大变更,我们将更新"最后更新日期",并在法律要求的情况下提供额外通知。
在法律允许的范围内,您于更新后的隐私政策生效后继续使用本服务,即表示您已知悉修订后的隐私政策。
联系我们
如您对本隐私政策或我们处理个人资料的方式有任何问题、疑虑或请求,请通过以下方式联系我们:
Flux Art
MORNING STAR INDUSTRY LIMITED
网站:https://flux-art.ai
客服邮箱:[email protected]
隐私/法务邮箱:[email protected]
注册地址:RM 19, UNIT C1, 6/F, KAISER ESTATE PHASE 1, 41 MAN YUE STREET, HUNG HOM HK