Effective Date: July 1, 2026
Last Updated: June 17, 2026
Data User: 聚元智算科技有限公司(TMax AI Limited)
Governing Law: Laws of the Hong Kong Special Administrative Region, including the Personal Data (Privacy) Ordinance (Cap. 486)
Table of Contents
- Introduction
- Definitions
- Information Collection
- Purpose of Information Use
- Information Sharing
- Special Notes on API Data Processing and AI Services
- Data Security
- User Rights
- Cookies Policy
- Children's Privacy
- International Data Transfer
- Policy Changes
- Contact Information and Complaint Channels
1. Introduction
聚元智算科技有限公司(TMax AI Limited) ("we", "our", or "the Company") respects and is committed to protecting your personal data privacy. This Privacy Policy ("this Policy") aims to explain to you, in accordance with the Personal Data (Privacy) Ordinance, Cap. 486 ("the Ordinance") and other applicable laws and regulations, how we collect, use, store, share, and protect your personal data when you use the TMax AI Intelligent Routing Platform ("the Platform") and related services (collectively, "the Services").
This Policy applies to all personal data we collect through the Platform and Services. We strongly recommend that you carefully read this Policy to understand how we handle your personal data and the rights you have.
If you do not agree with any content of this Policy, please stop using the Services. Your continued use of the Services constitutes your acceptance of this Policy and any revised versions thereof.
2. Definitions
In this Policy, unless the context otherwise requires:
- "Personal Data" refers to personal data as defined in Section 2 of the Ordinance, meaning data relating directly or indirectly to a living individual, from which it is practicable for the identity of the individual to be ascertained, and in a form in which access to or processing of the data is practicable;
- "Data User" refers to a person who, either alone or jointly or in common with other persons, controls the collection, holding, processing or use of personal data, as defined under the Ordinance, and in this Policy refers to the Company;
- "Data Subject" refers to a living individual who is the subject of personal data, as defined under the Ordinance, and in this Policy refers to you;
- "Usage Data" refers to data automatically generated during your use of the Services, including API call records, traffic logs, access timestamps, etc.;
- "LLM Provider" refers to third-party large language model service providers aggregated through the Platform;
- "Cookies" refers to small text files stored on your device, including HTTP Cookies, Flash Cookies, and similar technologies.
3. Information Collection
We collect your personal data lawfully and fairly in accordance with Data Protection Principle 1 of the Ordinance, and inform you of the purpose of data collection. The categories of information we collect are as follows:
3.1 Personal Data
When you register for an account and use the Services, we may collect the following personal data:
| Category |
Specific Content |
Collection Method |
| Identity Information |
Name, username |
Actively provided during registration |
| Contact Information |
Email address, phone number |
Actively provided during registration |
| Business Information |
Company name, position, business registration number, license number |
Provided during business verification |
| Identity Verification |
ID document number (for real-name authentication), document photos |
Provided during real-name authentication |
| Account Information |
Password (encrypted storage), API Key, security questions and answers |
Created during registration and settings |
3.2 Usage Data
When you use the Services, we automatically collect the following data:
| Category |
Specific Content |
Collection Purpose |
| API Call Records |
Call time, model type, token usage, request/response metadata |
Billing, service optimization |
| Traffic Logs |
IP address, request path, response status code, response time |
Security monitoring, troubleshooting |
| Device Information |
Browser type, operating system, screen resolution |
Compatibility optimization |
| Console Operation Logs |
Login time, operation type, page access records |
Security audit |
3.3 Payment Information
When you make payments or top-ups:
- We process your payment information through third-party payment service providers (such as Alipay, WeChat Pay, Stripe, etc.);
- We do not directly collect or store your bank card number, CVV code, or other sensitive payment information;
- We only retain payment transaction records (transaction ID, amount, time, payment method type) for account reconciliation and invoice issuance;
- Third-party payment service providers are bound by their respective privacy policies. We advise you to review the relevant service provider's privacy policy.
3.4 Cookies and Tracking Technologies
We use Cookies and similar technologies to collect specific information. See Section 9 "Cookies Policy" for details.
4. Purpose of Information Use
We collect your personal data only for the following purposes, and each use is directly related to the collection purpose:
4.1 Service Provision
Process your API call requests, manage your account, provide technical support, send service notifications and system announcements.
4.2 Billing and Settlement
Calculate API call fees, generate bills, process payments, manage account balances, provide invoices and receipts.
4.3 Security Monitoring
Detect and prevent fraudulent activities, abuse, unauthorized access, network attacks, and other security threats; verify user identity; enforce reasonable use policies.
4.4 Service Improvement
Analyze usage patterns to optimize routing strategies, enhance platform performance, and develop new features. We only use de-identified and aggregated data for analysis, without using raw data that can identify individuals.
4.5 Legal Compliance
Comply with applicable laws, regulations, regulatory requirements, and legal procedures, including but not limited to responding to lawful requests from law enforcement, cooperating with investigations and litigation proceedings.
4.6 Communication
Send service-related notifications, security alerts, billing reminders, and communications you request. We will not send you marketing emails without your consent.
5. Information Sharing
We do not sell, rent, or trade your personal data. We only share your personal data under the following circumstances:
5.1 LLM Providers
When you call specific LLM providers' models through the Platform, your request content (including prompts and input data) will be transmitted to that LLM provider to complete the request processing. This is necessary for providing the Services.
- The content and scope of transmission depend on the model you call and the request parameters;
- Each LLM provider is bound by its own privacy policy for the data it receives;
- We will provide links to major LLM providers' privacy policies in the console for your reference;
- If you do not wish your data to be transmitted to a specific LLM provider, you may choose not to call that provider's model.
5.2 Payment Service Providers
When processing your payments, we share necessary payment information (such as transaction amount, order ID) with third-party payment service providers. Payment service providers are bound by their respective privacy policies.
5.3 Legal Requirements
We may disclose your personal data under the following circumstances:
- As required by laws, court orders, or requests from government or regulatory authorities;
- To protect the rights, property, or safety of the company, users, or the public;
- To investigate or prevent fraud, security vulnerabilities, or violations of this Agreement;
- As required by the Personal Data (Privacy) Ordinance, Cap. 486, or other applicable laws.
5.4 Business Transfer
If the company undergoes a merger, acquisition, restructuring, or sale of all or part of its assets, your personal data may be transferred to the successor entity. In such transactions, we will require the successor entity to continue to be bound by this Policy, and will notify you when there are material changes to privacy practices.
5.5 Service Providers
We may engage third-party service providers to process your personal data, but only for the purposes described in this Policy:
- Cloud infrastructure service providers (server hosting and data storage);
- Email service providers (sending notifications and communications);
- Security audit service providers (vulnerability scanning and security assessment);
- Data analysis service providers (aggregated data analysis).
All third-party service providers are contractually bound to process personal data according to our instructions and applicable laws, and to take appropriate protective measures.
6. Special Notes on API Data Processing and AI Services
6.1 Data Flow
When you make an API request through the Platform, the data processing flow is as follows:
- Your request (including prompts and input parameters) is transmitted to our server through an encrypted connection;
- Our routing engine forwards the request to the LLM provider you specified or the system selected;
- The LLM provider processes the request and returns the generated content;
- The generated content is transmitted back to you through an encrypted connection.
Important Notice: Your request content (prompts and input data) will be transmitted to the corresponding LLM provider in Step 2. Each LLM provider has its own independent processing policy for the data it receives. Please review the relevant provider's privacy policy before using their services. We recommend that you do not include sensitive personal data (such as ID numbers, bank account information, medical records, etc.) in your prompts.
6.2 Processing of Prompts
- We do not use your prompts or input data to train, fine-tune, or improve any machine learning models;
- Your prompts are only temporarily stored in our production system for the period necessary to complete API requests, and will be deleted within thirty (30) calendar days after the request is completed;
- We may conduct sampling reviews of API requests for security monitoring and abuse detection purposes, but such sampling reviews only focus on request patterns and compliance, without storing complete prompt content;
- Token usage metadata used for billing and auditing (excluding prompt content) will be retained in accordance with financial compliance requirements.
6.3 Processing of Generated Content
- Generated content returned by the LLM is not stored in our systems after being transmitted to you;
- Generated content is only accessible to you and the corresponding LLM provider;
- We cannot view or retrieve generated content that has been transmitted to you.
6.4 Model Provider Data Policies
Each LLM provider has its own independent data processing policy for data processed through its services. Links to major model provider policies are available in our console. We recommend that you carefully read and understand the data policies of specific models before using them, particularly regarding:
- Whether data is used for model training or improvement;
- Data retention periods;
- Data geographic processing locations.
6.5 Security Incident Notification
In the event of a security incident involving your personal data, we will:
- Notify affected users within seventy-two (72) hours of discovering the incident;
- Notifications will include: the nature of the incident, categories of personal data involved, possible impact range, remediation measures taken, and recommended preventive measures;
- Simultaneously report to the Office of the Privacy Commissioner for Personal Data, Hong Kong (if required by the Ordinance);
- Provide a detailed incident report upon completion of the investigation.
7. Data Security
7.1 Encryption Measures
We implement the following encryption measures to protect your personal data:
- Transmission Encryption: All communications with the Platform are encrypted using TLS 1.2 or higher;
- Storage Encryption: Personal data at rest is encrypted using AES-256 or equivalent strength encryption algorithms;
- Key Management: Encryption keys are managed through a professional key management system, stored separately from encrypted data, and regularly rotated.
7.2 Access Control
- We implement role-based access control (RBAC), with only authorized employees able to access personal data within the scope necessary for their duties;
- All access to personal data is logged and audited;
- Employee access rights are regularly reviewed, and promptly revoked upon resignation or transfer;
- We require all employees with access to personal data to sign confidentiality agreements.
7.3 Data Backup
- We regularly back up personal data with encryption, stored in separate geographic locations;
- Access to backup data is subject to equally strict access controls as production data;
- We regularly test data recovery procedures to ensure timely recovery in the event of data loss.
7.4 Security Assessment
- We regularly conduct security vulnerability scans and penetration testing;
- We engage independent security audit institutions for annual security audits;
- We have established a security incident response team and incident response procedures to ensure security incidents are promptly discovered, reported, and handled.
7.5 Limitations of Security Measures
While we implement reasonable security measures, no internet transmission or electronic storage can guarantee absolute security. We cannot guarantee the absolute security of personal information transmission and storage, but we commit to promptly taking remedial measures and notifying affected users when security vulnerabilities are discovered.
8. User Rights
Under the Ordinance and international best practices, you have the following personal data rights:
8.1 Right of Access
You have the right to submit a Data Access Request in accordance with Sections 18 and 22 of the Ordinance to obtain a copy of the personal data we hold about you.
- Access requests must be submitted in writing to our Privacy Officer (see Section 13 for contact details);
- We will respond to valid access requests within forty (40) days;
- In accordance with Section 19 of the Ordinance, we may charge a reasonable fee for access.
8.2 Right to Correction
You have the right to request correction of inaccurate personal data in accordance with Section 22 of the Ordinance.
- You can correct most personal data yourself through the console;
- For data that cannot be corrected yourself, you may submit a written request for correction;
- We will process valid correction requests within forty (40) days.
8.3 Right of Erasure
You have the right to request erasure of your personal data under the following circumstances:
- The purpose of collecting the personal data has been achieved and the data is no longer needed;
- You withdraw consent to the processing of personal data and there is no other legal basis for processing;
- Personal data has been unlawfully collected or processed;
- Legal requirements mandate erasure.
Erasure requests do not affect processing conducted based on lawful grounds before the request was made, nor do they affect records we are required by law to retain (such as financial and tax records).
8.4 Right to Data Portability
You have the right to request that we provide your personal data in a structured, commonly used, and machine-readable format, or to transfer it directly to a third party you designate (where technically feasible).
8.5 Right to Object
You have the right to object to our processing of your personal data based on legitimate interests. If you raise an objection, we will assess your request, and unless we have compelling legitimate grounds to continue processing, we will cease the relevant processing.
8.6 Right to Withdraw Consent
If we process your personal data based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted based on consent before withdrawal.
8.7 Right to Restrict Processing
Under the following circumstances, you have the right to request restriction of processing of your personal data:
- You dispute the accuracy of personal data and need time for us to verify;
- Processing is unlawful but you do not wish to delete;
- We no longer need the data but you need to retain it for legal proceedings.
8.8 How to Exercise Your Rights
You may exercise the above rights through the following methods:
- Self-service functions on the platform console;
- Email: privacy@tokenmax.ai;
- Written submission to our Privacy Officer.
To protect the security of your personal data, we may require identity verification before processing your request. We will respond to requests within thirty (30) calendar days, and complex requests may be extended to sixty (60) calendar days, in which case we will inform you of the reason for the extension.
9. Cookies Policy
9.1 Use of Cookies
We use Cookies and similar technologies to provide, protect, and improve our services. Cookies are small text files stored on your device that help us recognize your device, remember your preferences, and provide a better user experience.
9.2 Categories of Cookies
| Category |
Purpose |
Required |
Can Be Refused |
| Essential Cookies |
Maintain session state, authentication, security |
Yes |
No |
| Functional Cookies |
Remember your preferences (such as language, theme) |
No |
Yes |
| Analytics Cookies |
Understand how users use the Platform, optimize services |
No |
Yes |
| Advertising Cookies |
We currently do not use advertising Cookies |
No |
N/A |
9.3 Managing Cookies
- You can manage or delete Cookies through your browser settings. Different browsers have different management methods; please refer to your browser's help documentation;
- Refusing Essential Cookies may result in some service features being unavailable;
- We will not associate Cookies with the personal data you submit unless necessary for providing specific services.
9.4 Third-Party Cookies
Our pages may contain Cookies from third-party services (such as analytics tools, payment gateways). These third-party Cookies are bound by their respective privacy policies, and we cannot control how they are used.
10. Children's Privacy
This Service is not intended for children under sixteen (16) years of age. We do not knowingly collect personal data from children under sixteen.
- If you are a child under sixteen, please do not use this Service or submit personal data to us;
- If you are a parent or guardian and discover that your child has provided us with personal data without your permission, please contact us immediately, and we will delete the relevant data as soon as possible;
- If we knowingly collect personal data from children under sixteen, we will delete such data immediately.
We take reasonable measures during the registration process to verify users' ages, including but not limited to requiring users to confirm they are over eighteen (18) years of age. If we discover that a user has provided false age information, we have the right to immediately terminate their account.
11. International Data Transfer
Due to the nature of our services, your personal data may be transferred to locations outside Hong Kong:
11.1 Transfer Scenarios
- When calling LLM providers' models located overseas, your request content will be transmitted to that provider's servers;
- Our cloud infrastructure may be located in multiple regions;
- Some third-party service providers may be located overseas.
11.2 Transfer Safeguards
When conducting international data transfers, we ensure that:
- The receiving region has an appropriate data protection legal framework, or
- We have entered into data transfer agreements with recipients that comply with the requirements of Section 33 of the Ordinance, ensuring personal data is protected at a level no less than Hong Kong law after transfer;
- All cross-border transfers use encrypted connections.
12. Policy Changes
12.1 Right to Modify
We reserve the right to modify this Policy at any time. Modified policies will be published on this Platform.
12.2 Notification Mechanism
- Material Changes: For changes that have a substantial impact on personal data processing methods (such as adding new information collection categories, changing information sharing scope, etc.), we will notify you at least thirty (30) calendar days in advance via email or platform announcement;
- Minor Changes: Changes that do not affect your rights and obligations will take effect immediately upon publication.
12.3 User Consent
If changes involve expanding the scope of personal data use or adding new collection categories, and such changes exceed the scope of original consent, we will seek your explicit consent separately. You have the right to refuse the changes, but this may affect your ability to use some service features.
13. Contact Information and Complaint Channels
13.1 Contact Us
If you have any questions, comments, or complaints about this Privacy Policy or our personal data processing practices, please contact us through the following methods:
- Company Name: 聚元智算科技有限公司(TMax AI Limited)
- Privacy Officer Email: privacy@tokenmax.ai
- Legal Affairs Email: legal@tokenmax.ai
- General Enquiries Email: support@tokenmax.ai
- Registered Address: Hong Kong Special Administrative Region
13.2 Office of the Privacy Commissioner for Personal Data, Hong Kong
If you believe that our handling of your personal data violates the Ordinance, you have the right to make a complaint to the Office of the Privacy Commissioner for Personal Data, Hong Kong:
- Address: 12/F, Sun Hung Kai Centre, 248 Queen's Road East, Wan Chai, Hong Kong
- Telephone: (852) 2827 2827
- Fax: (852) 2877 7026
- Email: enquiry@pcpd.org.hk
- Website: www.pcpd.org.hk
13.3 Regulatory Authorities in Other Jurisdictions
If you are located outside Hong Kong, you may also make complaints to the data protection authority in your jurisdiction. For example:
- European Union / European Economic Area: Local data protection supervisory authority (if GDPR applies)
- Mainland China: Cyberspace Administration of China or provincial cyberspace administration departments
13.4 How to Submit Data Access Requests
To submit a Data Access Request under the Ordinance, please mail your written request to our registered address, marked "Attention: Privacy Officer," and include a copy of your identity document.
© 2026 TMax AI Limited. All rights reserved.
This Privacy Policy is governed by the laws of the Hong Kong Special Administrative Region, including the Personal Data (Privacy) Ordinance (Cap. 486).
This Policy was last updated on June 17, 2026