Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.anygen.io/llms.txt

Use this file to discover all available pages before exploring further.

Foreword

AnyGen provides powerful AI agent services, including but not limited to AI-powered research and analysis, automated content generation across documents, spreadsheets and slides, end-to-end handling of complex tasks, native integration with Lark, and cross-platform data connectivity, all boasting high extensibility and availability.AnyGen attaches great importance to the data security of its customers and protecting the privacy of customers’ users. In the process of product design and development, AnyGen adhered to the concepts of “Privacy by Design” and “Privacy by Default” and committed itself to providing its customers with a transparent, trustworthy, secure, reliable, efficient and collaborative AI experience.We would like to take this white paper as an opportunity to share with you AnyGen’s basic principles and privacy management practices in this area.

Basic Principles for Personal Data Processing

AnyGen has determined its basic principles for personal data processing in accordance with applicable laws and regulations and ensured that the following basic principles are followed when processing personal data through appropriate management and technical measures:
  • Lawfulness, Legitimacy and Transparency: Personal data should be processed lawfully, fairly and in a transparent manner. - Purpose Limitation: Personal data should be processed for a specified, clear purpose and not further processed in a manner that is incompatible with that purpose. - Data Minimization: Personal data should be adequate, relevant and limited to what is necessary in relation to the purpose for which it is processed. - Accuracy: Personal data should be accurate and kept up to date where necessary. Reasonable measures will be taken to ensure that inaccurate personal data are deleted or corrected in a timely manner based on the purpose of the data processing. - Storage Limitation: Personal data should not be stored for longer than necessary to achieve the purpose for which the personal data is processed. - Integrity and Confidentiality: Personal data should be processed in a manner that ensures appropriate security of the personal data, prevents unauthorized access to or modification of the personal data, and avoids damage or loss of the personal data, using appropriate technical and organizational measures. - Accountability: Records relating to data processing and privacy controls must be maintained to demonstrate compliance with the above principles when necessary.

AnyGen’s Privacy Protection Management System

2.1 Privacy Protection Organization and Personnel

Compliance Team

AnyGen has a dedicated compliance team in place, which works together with multiple legal, security and other teams in the countries and regions with its business presence, to provide professional support for various compliance practices including privacy protection. Its responsibilities include but are not limited to the establishment, operation and optimization of data compliance management systems, and the development of product-based data compliance capabilities and solutions, etc. AnyGen will ensure that our product itself meets the requirements of global laws and regulations on data compliance, and provide customers with better compliance functions and services.

Publicity and Training Programs on Compliance

AnyGen conducts regular training and publicity programs on compliance for all personnel through various forms, including general knowledge training programs based on the requirements of global laws and regulations on data compliance and special training programs for employees in key positions, so as to enhance the awareness of all personnel for data protection and reduce compliance risks.

2.2 Life-cycle Management for Personal Data Processing

Data Collection

AnyGen strictly follows the principles of lawfulness, legitimacy, transparency and data minimization, and collects personal data necessary to provide services in an appropriate manner and frequency. Before collecting personal data, we will disclose the type of personal data collected, the purpose and method of collection in the Privacy Policy, and obtain the user’s consent in accordance with applicable laws and regulations. At the same time, AnyGen also provides a number of privacy setting functions. Users can withdraw the consent granted at any time through the privacy setting or by contacting the AnyGen team.

Data Use

AnyGen strictly abides by the principle of purpose limitation and will only use the collected personal data for the purpose of use authorized by the customers and users. By default, AnyGen’s employees do not have access to the personal data mentioned above, and all employees’ operations are strictly restricted and audited.

Data Sharing

Personal data processed by AnyGen is only disclosed in accordance with our Privacy Policy. In cases where AnyGen needs to share personal data with third parties, AnyGen strictly reviews third parties’ capabilities and qualifications for data security compliance, and uses reasonable efforts to require third parties to protect data in accordance with its high standards.

Data Retention and Disposal

We will retain your personal data for the length of time needed to fulfill the purposes outlined in Privacy Policy unless a longer retention period is required, for example to comply with legal obligations or requests or for the establishment, exercise or defense of legal claims, or for legitimate business purposes, or as provided by law.

2.3 Protection of Data Subject Rights

AnyGen allows users to submit data subject rights requests to customers. If the situation requires the coordination of AnyGen, the customers can contact AnyGen through the corresponding Customer Success Manager for assistance.AnyGen has a dedicated compliance team in place to be responsible for the management and operation of the above-mentioned channel to respond to data subject rights requests and to ensure that the response is in accordance with the relevant compliance requirements.

2.4 Management of Data Residency

AnyGen has established a data center node in Singapore.Circumstances involving the cross-border transfer of personal data for AnyGen itself shall be subject to strict legal and security compliance assessments. We rely on permitted legal bases and exceptions and will comply with requirements under applicable laws, in relation to such transfers. At the same time, AnyGen will also take appropriate management and technical measures to ensure the security of data transmission.

2.5 Privacy Risk Management

Privacy Impact Assessment (PIA)

AnyGen has been extensively implementing the concepts of “Privacy by Design” and “Privacy by Default”, embedding the basic principles of privacy protection throughout the design, development and operation process of product requirements. For business functions or scenarios related to personal data processing, a privacy impact assessment shall be conducted to assess the types of personal data involved, the purpose and method of processing, and the possible impact on the rights and interests of data subjects. For the identified medium-and high-risk items, corresponding risk rectifications shall be carried out according to the established risk mitigation measures to reduce the privacy risk.

Risk Scanning for Security Compliance

Before and after the release of each application version of AnyGen, strict risk scanning for security compliance will be conducted to identify and dispose of relevant risk items in a timely manner to ensure the security of customers’ data and privacy.Before the release of an application version, static code scanning will be conducted on the application. After the release of the version, each product module will be regularly tested for security compliance risks. For the variously identified medium-and high-risk security vulnerabilities, privacy compliance problems, etc., they will be fixed and rectified within a limited time frame.

2.6 Response to Data Leak Events

AnyGen has established robust information security management and internal control related systems and processes, and employs identification and access management, data encryption, de-identification, security compliance scanning, Penetration Testing, security information and event management platform (SIEM) and other technical means and tools to guard against potential security events.In case of data leakage events, the security and compliance team will immediately and properly handle the events in accordance with the relevant event management process and contingency plans, report them to the regulators in a timely manner in accordance with applicable laws and regulations, and notify customers, users or relevant parties that may be affected. In addition, the events will be reviewed and summarized after they have been dealt with, and relevant improvement measures will be taken to prevent the recurrence of similar events.

2.7 Data Security

For more information about data security practices, please refer to AnyGen Security Whitepaper.

AnyGen’s Security and Privacy Compliance Certification

AnyGen has secured ISO 27001, this certificate is widely recognized by the industry in the field of information security management as an internationally authoritative certification. This certification indicates that AnyGen has already aligned itself with international standards in this field and met the security standards required by this certification.

Conclusion

AnyGen respects its customers’ global IT strategy and international development needs, is willing to make long-term investments, and provides customers with relevant capabilities through various security compliance solutions on the basis of fully understanding customers’ demands for data security and privacy protection, to help them cope with the security challenges resulting from the open and complicated network environment, as well as the increasingly stringent requirements for global data compliance and privacy protection, and is open to more in-depth cooperation in the field of security compliance.

Version Change Record

DateVersionRemarks
18 May 20261.0Initial release