1. Scope
Changé is committed to handling your personal data fairly, responsibly, and transparently. This Privacy Policy explains how we collect, hold, process, use, disclose, and protect personal data when you use our AI assistant, workspaces, file processing, organization collaboration, marketplace publishing, subscriptions, payments, and related services, and how you may exercise your rights.
This policy applies where we determine the purposes and means of processing personal data for Changé. If an enterprise customer separately instructs us to process data on its behalf, a data processing agreement or enterprise agreement may supplement this policy. If you access Changé through an independent third-party service, that third party's privacy policy applies to data it collects independently.
Please read this policy carefully. If you do not agree with it, do not register for, access, or continue using Changé.
2. Who We Are
Changé in Hong Kong is operated and provided by 基础科技(香港)有限公司 (Fundamental).
For this Privacy Policy, unless a page, order, or separate agreement states otherwise, “we,” “us,” “the platform,” and “Changé” refer to the service provider above.
We are the principal data user for the personal data described in this policy. Third-party payment, identity, or external services that independently determine their processing activities may be separate data users.
- Company name: 基础科技(香港)有限公司 (Fundamental)
- Company address: Unit 2962, 29th Floor, Infinitus Plaza, 199 Des Voeux Road Central, Sheung Wan, Hong Kong
- Customer service hotline: +852-66415338
- Contact email: service@fundamental.com.hk
3. Information We Collect
We may collect the following data directly from you, from an organization or login service you authorize, from payment and technology providers, or automatically when you use the service. Unless stated otherwise, core account data, User Content, and necessary technical data are required to perform the service; refusing to provide them may prevent the relevant feature from working.
Account, Verification, and Organization Data
This includes email address, username, display name, avatar, account and session identifiers, verification records, login status, device name, and organization or space memberships, roles, and permissions. It comes from you, a login service you authorize, or an organization administrator. We use it for registration, login, identity verification, permission management, account support, and security, and may disclose it to identity, email, security, and infrastructure providers.
User Content and AI Outputs
This includes prompts, messages, instructions, workspace context, and text, code, links, images, audio, video, office files, source materials, and extraction results that you upload, preview, or process. Responses, files, summaries, and other outputs are processed together with the related inputs. This data comes directly from you or a data source you authorize. We use it to fulfill requests, preserve history, enable collaboration, troubleshoot, and protect the service, and may disclose it to model inference, search, file processing, content generation, cloud computing, and security providers.
Collaboration, Publishing, and Feedback Data
This includes space messages, member interactions, role changes, shared files, template or skill listings, web publications, visibility settings, installation and usage records, ratings, message reactions, reports, and moderation results. It comes from you and other collaborators. We use it to enable collaboration, display content to the audience you select, record feedback, handle reports, and protect the platform, and may disclose it to relevant space members, visitors to published content, and providers supporting collaboration and safety.
Technical, Usage, and Security Data
This includes IP address and general area inferred from it, device and browser type, operating system, access time, feature usage, request status, duration, errors, runtime logs, login and security events, risk signals, and audit records. It is generated automatically when you use the service. We use it to operate and scale the service, troubleshoot, prevent fraud and attacks, enforce content safety rules, and meet audit requirements, and may disclose it to cloud, network, monitoring, logging, and security providers.
Subscription, Order, and Payment Data
This includes subscription tier, purchased item, billing cycle, order number, payment session status, payment method type, billing address, currency, amount, tax, payment confirmation, renewal, cancellation, resumption, upgrade, refund, chargeback, and dispute status, plus necessary risk and fulfillment data returned by payment providers. It comes from you and payment providers. We use it for payment, reconciliation, fulfillment, tax, anti-fraud, refunds, and disputes, and disclose it to payment processors, wallets, issuers, risk, and tax providers. We generally do not directly collect or store full card numbers, payment passwords, or security codes.
Support, Complaint, and Rights Request Data
This includes contact details, request content, relevant screenshots or evidence, communications, outcomes, and identity verification data where necessary. It comes directly from you. We use it to respond to support, complaints, appeals, data rights, and security requests, and may disclose it to support, legal, and security providers or legally authorized authorities.
4. How We Use Information
We use collected information to provide, maintain, protect, and improve Changé.
- Provide and improve AI chat, file processing, content generation, workspaces, organization permissions, and collaboration features.
- Create and maintain accounts, sessions, organizations, spaces, roles, permissions, and memberships.
- Send, verify, and protect against abuse of login or registration verification codes.
- Process subscriptions, one-time purchases, extra credit packages, recurring subscriptions, renewals, cancellations, resumptions, upgrades, refunds, disputes, tax calculation, billing address storage or prefilling, and grant, extend, convert, or adjust subscription benefits, credits, and space quotas after payment is completed.
- Receive payment confirmations, failures, cancellations, renewal charges, refunds, and payment risk status from payment and transaction fulfillment service providers for payment inquiry, reconciliation, fulfillment, risk control, notifications, and support handling.
- Use anonymous aggregate metrics that do not identify and cannot reasonably be linked back to a person or organization to analyze usage patterns, troubleshoot, optimize performance, and improve service stability and experience.
- Respond to your inquiries, support requests, permission handling, account issues, and security feedback.
- Detect and prevent fraud, abuse, abnormal logins, attacks, infringement, illegal activity, or rule violations.
- Comply with applicable laws and regulations, regulatory requirements, dispute handling, or lawful requests.
5. AI Processing, Training, and Human Access
Neither we nor third-party model providers supporting Changé use your conversations, files, collaboration data, or other User Content to train, fine-tune, or improve any platform or third-party model. We may use anonymous aggregate metrics that do not identify and cannot reasonably be linked back to a person or organization to assess feature performance and improve systems.
To generate results, necessary Inputs and context are sent to model, search, file processing, or generation services operating in API or enterprise processing modes. Providers may process data only on our instructions and may not use User Content for their own model training. They may retain necessary data for a short period for security, abuse prevention, or troubleshooting.
Authorized personnel may access User Content only to respond to your support request, investigate a major failure or security incident, address abuse, or comply with law, and only to the minimum extent necessary. Access is subject to permission controls, confidentiality obligations, and audit records.
AI Outputs may be inaccurate or incomplete and may contain personal data provided in Inputs. If an Output contains potentially inaccurate personal data about you, contact the privacy email below. Because of model limitations, we may not be able to alter model parameters directly, but we will take reasonably practicable steps regarding related records, displays, or subsequent use.
6. Data Protection and Security
We take appropriate technical and organizational measures to protect your personal information, workspace data, and uploaded materials.
- Use encryption or equivalent protection for data in transit and storage within reasonable limits.
- Limit data access through account, organization, space, role, and permission mechanisms.
- Allow authorized personnel to access personal information or business data only when necessary and within the required scope.
- Keep necessary operation audits, security logs, and abnormal access records for troubleshooting, accountability, and security protection.
- Regularly assess security risks and improve safeguards based on actual conditions.
- No method of internet transmission or electronic storage can be guaranteed 100% secure. Although we work to protect your information, we cannot promise absolute security.
- If a security incident may affect personal data, we will promptly contain and investigate it and take remedial measures. We will notify affected individuals and relevant regulators where required by applicable law or where notice would help avoid significant harm.
7. Cookies and Tracking Technologies
We use cookies, local storage, session storage, or similar technologies only for login, preferences, security, and necessary operation. We do not use them for advertising, cross-site tracking, or third-party marketing analytics.
- Remember your login status, device information, recently used email address, interface preferences, or other necessary settings.
- Record necessary session and operational state to maintain features, performance, and stability.
- Help identify abnormal access, attacks, abuse, or rule violations.
- You can control or clear related technology data through your browser settings, but disabling it may affect login, session persistence, or normal use of some features.
- We send only necessary messages such as verification codes, order and payment updates, security and service notices, support replies, and legal-policy updates. We currently do not use your email for product promotions, events, or offers. If we introduce direct marketing, we will first obtain any consent required by law and provide a free unsubscribe method in every communication.
8. Automated Processing and Human Review
To protect users and the platform, systems may use login, payment, content, or usage risk signals to trigger verification, request blocking, payment review, content restrictions, quota limits, or temporary account protection. We do not rely solely on automated processing to make decisions where prohibited by law.
If an automated measure significantly affects your account, paid benefits, or use of the service, you may request human review through the privacy contact email. We will review relevant risk signals, account and transaction records, and tell you the result or what additional information is needed.
9. Third-Party Services
We may share necessary information with third-party service providers that help us operate Changé.
- Cloud hosting, database, storage, compute, and network infrastructure providers.
- Email delivery, verification code, security protection, monitoring, logging, troubleshooting, and analytics services.
- AI model inference, internet search, file processing, content generation, or media generation services.
- Payment, subscription, and transaction fulfillment service providers, including services shown on the page or configured in the backend for cards, wallets, refunds, payment inquiries, recurring subscriptions, and transaction risk control.
- Tools required for customer support, tickets, notifications, or organization collaboration.
- When you enter the payment flow, manage a recurring subscription, or ask us to handle a payment issue, we provide payment service providers with information necessary to complete payment, recurring billing, cancellation, resumption, upgrade, refund, tax calculation, billing, payment inquiry, reconciliation, and risk control. Payment credentials you enter on a third-party checkout or wallet page are usually collected and processed directly by that payment service provider.
- Recipients of data required in connection with a corporate restructuring, merger, financing, acquisition, bankruptcy, or asset transfer, and courts, regulators, law enforcement, or other authorized bodies receiving data to comply with law, enforce agreements, or protect users or the platform.
- Third-party service providers may process only the data necessary for the purposes we specify, must apply safeguards appropriate to their roles, and may not use User Content to train, fine-tune, or improve their models. We do not sell personal data or provide it to third parties for their advertising, cross-site tracking, or independent marketing.
10. Hong Kong Storage and Cross-Border Processing
Changé's primary databases, user files, operational records, and persistent backups are stored in Hong Kong.
To provide model inference, internet search, file processing, content generation, security, or payment features, necessary data may be sent over encrypted connections to service providers outside Hong Kong for immediate processing. Those providers may retain necessary data for a short period for security, abuse prevention, or troubleshooting. This overseas processing does not change the platform's arrangement to keep its primary persistent storage in Hong Kong.
We minimize the data sent, contractually restrict processing purposes and training use, assess provider safeguards, and apply access controls, transmission protection, and retention limits. Do not include sensitive or confidential data that is unnecessary to complete your request.
11. Collaboration Spaces, Organizations, and Public Publishing
Messages, files, and runtime records in a collaboration space are available by default only to members of that space. Organization administrators may manage organization members, subscriptions, quotas, and usage statistics, but do not automatically gain access to content in spaces they have not joined. If an administrator becomes a space member, access follows that space role.
Space owners and authorized members may invite or remove members, change roles, and manage space content. After a member leaves or is removed, content previously contributed as part of the collaborative record may remain in the space to preserve shared work, audits, and dispute handling.
If you publish a space template, skill, file result, or webpage to a marketplace, public link, or other public audience, visitors may view, download, install, copy, capture, or redistribute that data. Confirm before publishing that the content contains no personal, sensitive, or confidential data that should not be public.
12. Your Rights
Under Hong Kong's Personal Data (Privacy) Ordinance, you may request access to personal data we hold about you and correction of inaccurate personal data. Where applicable, you may also request deletion, account closure, restriction of certain processing, withdrawal of consent, or make a complaint or request human review of an automated measure.
Submit requests to service@fundamental.com.hk and identify the request type, relevant account, and information sufficient to locate the data. To protect data, we may verify your account, identity, and authority. We may charge a reasonable fee for a data access request as permitted by law, limited to the cost of processing it.
We will respond to a valid request as soon as practicable and within the period required by Hong Kong law. Data access or correction requests are generally handled within 40 days. If we lawfully need more time, refuse a request, or retain some data, we will explain the applicable reason.
- Access personal data we hold about you and obtain an applicable copy.
- Request correction of inaccurate or incomplete personal data.
- Where applicable, request deletion, account closure, or cessation of non-essential processing.
- Withdraw consent-based processing without affecting the lawfulness of earlier processing.
- Request an explanation of an automated measure and ask for human review.
- You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong at https://www.pcpd.org.hk/.
13. Data Retention
We retain personal data only for as long as necessary for the purposes in this policy, contractual performance, security, disputes, or legal obligations. The period depends on the nature of the data, account and space status, user choices, risk, audit requirements, and statutory obligations.
Account, conversation, workspace, and file data is generally retained while the account or relevant feature remains active and as needed to provide the service. When you delete data through the interface, it leaves normal use or is marked deleted, but this does not mean every system copy is physically erased immediately. When the purpose no longer requires the data and law permits, we delete or anonymize it according to system and backup life cycles.
Order, subscription, payment notification, billing address, refund, dispute, reconciliation, finance, and tax-related records may be retained while your account exists and for as long as necessary to perform contracts, financial, tax, audit, anti-fraud, dispute handling, or legal obligations. Even if you cancel a subscription, close your account, or request deletion of some materials, we may continue retaining necessary transaction records to the extent permitted or required by law.
Security, login, runtime, support, and audit records are retained as needed for troubleshooting, security, and compliance. Retention may be extended for a security incident, dispute, investigation, or legal hold. Residual copies in backups and caches remain isolated and protected during their controlled life cycle and are erased or overwritten when no longer needed.
14. Children's Privacy
Children under 13 may not register for, access, or use Changé, and we do not knowingly collect their personal data.
Users who are at least 13 but under 18 must use the service with the prior consent and guidance of a parent or legal guardian and may not purchase subscriptions, credits, space quotas, or other paid services. Guardians should help minors avoid submitting their own or another person's sensitive data.
If you believe a child under 13 or a minor without appropriate guardian consent provided personal data to us, contact service@fundamental.com.hk. After verification, we will restrict the relevant account and delete the data or take other appropriate action as required by law.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When changes occur, we will publish the new Privacy Policy on this page and update the Last updated date.
If a change significantly affects your personal data rights, we will also notify you through an in-product notice, station message, email, or another appropriate method and obtain consent again where required by law. You may stop using the relevant service before the change takes effect.
16. Contact
For questions or complaints about this policy, personal data processing, security incidents, account closure, children's data, automated measures, or data access and correction requests, please contact us primarily through the privacy email below.
- Company name: 基础科技(香港)有限公司 (Fundamental)
- Company address: Unit 2962, 29th Floor, Infinitus Plaza, 199 Des Voeux Road Central, Sheung Wan, Hong Kong
- Customer service hotline: +852-66415338
- Privacy contact email: service@fundamental.com.hk
- Company website: https://fundamental.com.hk/