Policies

Privacy Policy

Your privacy matters to us. This policy explains how we collect, use, and protect your information.

1. Scope

Changé is committed to handling your personal data fairly, responsibly, and transparently. This Privacy Policy explains how we collect, hold, process, use, disclose, and protect personal data when you use our AI assistant, workspaces, file processing, organization collaboration, marketplace publishing, subscriptions, payments, and related services, and how you may exercise your rights.

This policy applies where we determine the purposes and means of processing personal data for Changé. If an enterprise customer separately instructs us to process data on its behalf, a data processing agreement or enterprise agreement may supplement this policy. If you access Changé through an independent third-party service, that third party's privacy policy applies to data it collects independently.

Please read this policy carefully. If you do not agree with it, do not register for, access, or continue using Changé.

2. Who We Are

Changé in Hong Kong is operated and provided by 基础科技(香港)有限公司 (Fundamental).

For this Privacy Policy, unless a page, order, or separate agreement states otherwise, “we,” “us,” “the platform,” and “Changé” refer to the service provider above.

We are the principal data user for the personal data described in this policy. Third-party payment, identity, or external services that independently determine their processing activities may be separate data users.

3. Information We Collect

We may collect the following data directly from you, from an organization or login service you authorize, from payment and technology providers, or automatically when you use the service. Unless stated otherwise, core account data, User Content, and necessary technical data are required to perform the service; refusing to provide them may prevent the relevant feature from working.

Account, Verification, and Organization Data

This includes email address, username, display name, avatar, account and session identifiers, verification records, login status, device name, and organization or space memberships, roles, and permissions. It comes from you, a login service you authorize, or an organization administrator. We use it for registration, login, identity verification, permission management, account support, and security, and may disclose it to identity, email, security, and infrastructure providers.

User Content and AI Outputs

This includes prompts, messages, instructions, workspace context, and text, code, links, images, audio, video, office files, source materials, and extraction results that you upload, preview, or process. Responses, files, summaries, and other outputs are processed together with the related inputs. This data comes directly from you or a data source you authorize. We use it to fulfill requests, preserve history, enable collaboration, troubleshoot, and protect the service, and may disclose it to model inference, search, file processing, content generation, cloud computing, and security providers.

Collaboration, Publishing, and Feedback Data

This includes space messages, member interactions, role changes, shared files, template or skill listings, web publications, visibility settings, installation and usage records, ratings, message reactions, reports, and moderation results. It comes from you and other collaborators. We use it to enable collaboration, display content to the audience you select, record feedback, handle reports, and protect the platform, and may disclose it to relevant space members, visitors to published content, and providers supporting collaboration and safety.

Technical, Usage, and Security Data

This includes IP address and general area inferred from it, device and browser type, operating system, access time, feature usage, request status, duration, errors, runtime logs, login and security events, risk signals, and audit records. It is generated automatically when you use the service. We use it to operate and scale the service, troubleshoot, prevent fraud and attacks, enforce content safety rules, and meet audit requirements, and may disclose it to cloud, network, monitoring, logging, and security providers.

Subscription, Order, and Payment Data

This includes subscription tier, purchased item, billing cycle, order number, payment session status, payment method type, billing address, currency, amount, tax, payment confirmation, renewal, cancellation, resumption, upgrade, refund, chargeback, and dispute status, plus necessary risk and fulfillment data returned by payment providers. It comes from you and payment providers. We use it for payment, reconciliation, fulfillment, tax, anti-fraud, refunds, and disputes, and disclose it to payment processors, wallets, issuers, risk, and tax providers. We generally do not directly collect or store full card numbers, payment passwords, or security codes.

Support, Complaint, and Rights Request Data

This includes contact details, request content, relevant screenshots or evidence, communications, outcomes, and identity verification data where necessary. It comes directly from you. We use it to respond to support, complaints, appeals, data rights, and security requests, and may disclose it to support, legal, and security providers or legally authorized authorities.

4. How We Use Information

We use collected information to provide, maintain, protect, and improve Changé.

5. AI Processing, Training, and Human Access

Neither we nor third-party model providers supporting Changé use your conversations, files, collaboration data, or other User Content to train, fine-tune, or improve any platform or third-party model. We may use anonymous aggregate metrics that do not identify and cannot reasonably be linked back to a person or organization to assess feature performance and improve systems.

To generate results, necessary Inputs and context are sent to model, search, file processing, or generation services operating in API or enterprise processing modes. Providers may process data only on our instructions and may not use User Content for their own model training. They may retain necessary data for a short period for security, abuse prevention, or troubleshooting.

Authorized personnel may access User Content only to respond to your support request, investigate a major failure or security incident, address abuse, or comply with law, and only to the minimum extent necessary. Access is subject to permission controls, confidentiality obligations, and audit records.

AI Outputs may be inaccurate or incomplete and may contain personal data provided in Inputs. If an Output contains potentially inaccurate personal data about you, contact the privacy email below. Because of model limitations, we may not be able to alter model parameters directly, but we will take reasonably practicable steps regarding related records, displays, or subsequent use.

6. Data Protection and Security

We take appropriate technical and organizational measures to protect your personal information, workspace data, and uploaded materials.

7. Cookies and Tracking Technologies

We use cookies, local storage, session storage, or similar technologies only for login, preferences, security, and necessary operation. We do not use them for advertising, cross-site tracking, or third-party marketing analytics.

8. Automated Processing and Human Review

To protect users and the platform, systems may use login, payment, content, or usage risk signals to trigger verification, request blocking, payment review, content restrictions, quota limits, or temporary account protection. We do not rely solely on automated processing to make decisions where prohibited by law.

If an automated measure significantly affects your account, paid benefits, or use of the service, you may request human review through the privacy contact email. We will review relevant risk signals, account and transaction records, and tell you the result or what additional information is needed.

9. Third-Party Services

We may share necessary information with third-party service providers that help us operate Changé.

10. Hong Kong Storage and Cross-Border Processing

Changé's primary databases, user files, operational records, and persistent backups are stored in Hong Kong.

To provide model inference, internet search, file processing, content generation, security, or payment features, necessary data may be sent over encrypted connections to service providers outside Hong Kong for immediate processing. Those providers may retain necessary data for a short period for security, abuse prevention, or troubleshooting. This overseas processing does not change the platform's arrangement to keep its primary persistent storage in Hong Kong.

We minimize the data sent, contractually restrict processing purposes and training use, assess provider safeguards, and apply access controls, transmission protection, and retention limits. Do not include sensitive or confidential data that is unnecessary to complete your request.

11. Collaboration Spaces, Organizations, and Public Publishing

Messages, files, and runtime records in a collaboration space are available by default only to members of that space. Organization administrators may manage organization members, subscriptions, quotas, and usage statistics, but do not automatically gain access to content in spaces they have not joined. If an administrator becomes a space member, access follows that space role.

Space owners and authorized members may invite or remove members, change roles, and manage space content. After a member leaves or is removed, content previously contributed as part of the collaborative record may remain in the space to preserve shared work, audits, and dispute handling.

If you publish a space template, skill, file result, or webpage to a marketplace, public link, or other public audience, visitors may view, download, install, copy, capture, or redistribute that data. Confirm before publishing that the content contains no personal, sensitive, or confidential data that should not be public.

12. Your Rights

Under Hong Kong's Personal Data (Privacy) Ordinance, you may request access to personal data we hold about you and correction of inaccurate personal data. Where applicable, you may also request deletion, account closure, restriction of certain processing, withdrawal of consent, or make a complaint or request human review of an automated measure.

Submit requests to service@fundamental.com.hk and identify the request type, relevant account, and information sufficient to locate the data. To protect data, we may verify your account, identity, and authority. We may charge a reasonable fee for a data access request as permitted by law, limited to the cost of processing it.

We will respond to a valid request as soon as practicable and within the period required by Hong Kong law. Data access or correction requests are generally handled within 40 days. If we lawfully need more time, refuse a request, or retain some data, we will explain the applicable reason.

13. Data Retention

We retain personal data only for as long as necessary for the purposes in this policy, contractual performance, security, disputes, or legal obligations. The period depends on the nature of the data, account and space status, user choices, risk, audit requirements, and statutory obligations.

Account, conversation, workspace, and file data is generally retained while the account or relevant feature remains active and as needed to provide the service. When you delete data through the interface, it leaves normal use or is marked deleted, but this does not mean every system copy is physically erased immediately. When the purpose no longer requires the data and law permits, we delete or anonymize it according to system and backup life cycles.

Order, subscription, payment notification, billing address, refund, dispute, reconciliation, finance, and tax-related records may be retained while your account exists and for as long as necessary to perform contracts, financial, tax, audit, anti-fraud, dispute handling, or legal obligations. Even if you cancel a subscription, close your account, or request deletion of some materials, we may continue retaining necessary transaction records to the extent permitted or required by law.

Security, login, runtime, support, and audit records are retained as needed for troubleshooting, security, and compliance. Retention may be extended for a security incident, dispute, investigation, or legal hold. Residual copies in backups and caches remain isolated and protected during their controlled life cycle and are erased or overwritten when no longer needed.

14. Children's Privacy

Children under 13 may not register for, access, or use Changé, and we do not knowingly collect their personal data.

Users who are at least 13 but under 18 must use the service with the prior consent and guidance of a parent or legal guardian and may not purchase subscriptions, credits, space quotas, or other paid services. Guardians should help minors avoid submitting their own or another person's sensitive data.

If you believe a child under 13 or a minor without appropriate guardian consent provided personal data to us, contact service@fundamental.com.hk. After verification, we will restrict the relevant account and delete the data or take other appropriate action as required by law.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When changes occur, we will publish the new Privacy Policy on this page and update the Last updated date.

If a change significantly affects your personal data rights, we will also notify you through an in-product notice, station message, email, or another appropriate method and obtain consent again where required by law. You may stop using the relevant service before the change takes effect.

16. Contact

For questions or complaints about this policy, personal data processing, security incidents, account closure, children's data, automated measures, or data access and correction requests, please contact us primarily through the privacy email below.

Privacy Policy | Changé