DealMate
  • Features
  • How It Works
  • Why DealMate
  • Pricing
Get Started
Contents
1. Who we are2. What this policy covers: our two roles3. Personal data we collect4. How we use personal data, and our legal bases5. How our AI Features process your content6. Who we share personal data with7. International transfers and access from mainland China8. How long we keep personal data9. How we protect personal data10. Your rights11. Cookies and similar technologies12. Children13. Information for specific regions14. Changes to this policy15. Contact us

DealMate Privacy Policy

International version·Version 1.0·Effective date: 1 October 2026·Terms of Service·View the Japanese translation

Contents
1. Who we are2. What this policy covers: our two roles3. Personal data we collect4. How we use personal data, and our legal bases5. How our AI Features process your content6. Who we share personal data with7. International transfers and access from mainland China8. How long we keep personal data9. How we protect personal data10. Your rights11. Cookies and similar technologies12. Children13. Information for specific regions14. Changes to this policy15. Contact us

At a glance. This summary is for convenience only; the full policy below governs.

  • Who we are: the international version of DealMate is operated by InoAI Technology Co., Limited, a company incorporated in Hong Kong. A company in mainland China, 上海甄零科技有限公司 (Shanghai Zhenling Technology Co., Ltd.), develops, operates and supports the Service for us.
  • Our two roles: we are the controller of your account, sign-in, billing and log data. For the contracts and other documents you upload, we act on behalf of you or your organisation, as a processor (or "service provider").
  • Where your data goes: our main servers are in Japan (Tokyo). To produce AI results, the text of your documents is sent to AI and document-processing providers, including DeepSeek in mainland China. The people who operate the Service can access data remotely from mainland China. Some of our providers are in the United States and Singapore.
  • AI training: we do not use your documents to train AI models. Our AI providers' own commitments differ, and DeepSeek's terms say nothing either way (Section 5).
  • No selling, no advertising: we do not sell personal data, and we use no advertising or analytics cookies.
  • Your choice: when you sign up, you tick a checkbox to agree to our terms and this policy — including, expressly, that the content you upload is processed by AI providers in mainland China. Without it, you cannot create an account.
  • Your rights: change your details or close your account yourself in your account settings; email cs@onecontract-cloud.com for anything else.

1. Who we are

The international version of DealMate (the "Service") is operated by InoAI Technology Co., Limited, a company incorporated in Hong Kong ("DealMate", "we", "us" or "our"). 上海甄零科技有限公司 (Shanghai Zhenling Technology Co., Ltd.) ("Shanghai Zhenling"), a company in mainland China, develops, operates and supports the Service on our behalf (Section 6.1).

  • Contact, including for privacy questions and requests: cs@onecontract-cloud.com
  • Data Protection Officer, who handles requests to access or correct your personal data: 4/F, Building B, No. 33 Huilian Road, Qingpu District, Shanghai, People's Republic of China; email: cs@onecontract-cloud.com. Our Data Protection Officer is an employee of Shanghai Zhenling, which handles these requests on our behalf.
  • We will tell you our address and the name of our representative without delay on request.
  • The Service is not directed at people in the European Economic Area, the United Kingdom or Switzerland, and we have not appointed representatives there.

2. What this policy covers: our two roles

2.1 As controller. We decide how and why we use personal data about our users and website visitors — account and sign-in data, billing data, support communications, security and usage logs, and cookies. This policy explains how we do that.

2.2 On behalf of our customers. The contracts and other documents you upload, the text you enter and the results the Service produces ("Customer Content") belong to our customer: you, or the organisation you use DealMate for. We process personal data in Customer Content only to provide the Service to that customer, on its instructions, under Section 8 of our Terms of Service. The customer decides what to upload, and is responsible for having a lawful basis for doing so and for informing the people named in its documents.

2.3 If you are named in someone else's document. Contracts often contain personal data about people who do not use DealMate — for example counterparties, signatories and contact persons. If you are one of them, please contact the customer who uploaded the document. If you contact us instead, we will pass your request to that customer and help it respond.

2.4 Transparency about Customer Content. Although the customer controls Customer Content, this policy also describes where Customer Content is sent (Sections 5 to 7) and how long we keep it (Section 8), so that customers, and the people named in their documents, can understand what happens to it.

2.5 What this policy does not cover. Third-party services you use with DealMate — such as Google, Microsoft, Apple or Alipay sign-in, and Stripe's payment pages — are covered by those companies' own privacy policies.

2.6 Terms we use. Capitalised terms that this policy does not define — such as "Outputs", "AI Features", "Points" and "Paid Plan" — have the meanings given in our Terms of Service.

3. Personal data we collect

3.1 Data you give us.

  • Account data: your email address, username and password (we store only a hash of your password, never the password itself), and the one-time codes we send to verify your email address or reset your password.
  • Display name: a nickname or your name, if you choose to set one in your account settings. We use it to address you in the Service; if you have not set one, we use your username.
  • Preferences: your interface language.
  • Communications: what you send us when you contact us.
  • Purchases: your plan, billing period, payment and refund history, amounts and currency, and the identifiers Stripe gives us for you and your subscription. Stripe collects your card details and billing address directly on its own pages; we do not receive your full card number.
  • Customer Content (processed for the customer, as described in Section 2.2): contract files (Word and PDF) and the text extracted from them; your messages to the drafting assistant and the deal details extracted from them (for example the parties, subject matter, amounts, dates and payment terms); the side you represent and your negotiating position; background facts you add when asking follow-up questions; your templates, clauses and review rules (each rule keeps a copy of the clause text it was extracted from); and all Outputs. So that you can search your documents, we also create numerical representations of their text (embeddings).

3.2 Data from sign-in providers (only if you choose to use them).

  • Google: your name, email address, profile picture link and Google account ID. We use this information only to create your account, sign you in and show your name and picture. We do not use it for advertising, and we do not transfer it to others except as needed to provide the Service or to comply with the law.
  • Microsoft: your name, the email address or username Microsoft provides, and identifiers for your Microsoft account and its organisation (object ID and tenant ID). Because this email address is not verified for us, we keep it only with your Microsoft sign-in record and do not use it as your contact email.
  • Apple: your Apple user ID; your email address — which may be a private relay address if you use Apple's "Hide My Email" — and whether it is a relay address; and your name, which Apple shares only the first time you sign in.
  • Alipay: your Alipay user ID, nickname and profile picture. Alipay does not give us your email address or phone number.

We also record when you last signed in with each method. We never receive your password for these services. If you remove a sign-in method from your account, we delete the information we received from that provider. If you withdraw DealMate's authorisation in your Alipay account, tell us and we will delete the information we received from Alipay.

3.3 Data from Stripe. Stripe tells us the status of your payments and subscription, including renewals, failed payments, refunds and disputes.

3.4 Data collected automatically.

  • IP address. We use your IP address (a) to limit how many requests can be made in a short time, which protects the Service from abuse — for this we keep it in a temporary store for up to one hour — and (b) to look up the country you connect from — on our own servers, without sending your IP address to anyone else — so that we can show you the right prices, sign-in options and version of our terms. We do not store IP addresses in our database.
  • Device and browser. We use your browser's user-agent string to choose a mobile or desktop layout (we keep the result in a cookie) and to hide sign-in options that do not work in some in-app browsers, and your browser's language setting to choose your interface language. If you sign in with Alipay from a mobile browser, we store your browser's user-agent string for a few minutes so that we can show you which device started the sign-in.
  • Usage and billing records. Your Points history (the action, the Points used, the time, the related item and, for some actions, the file name) and a record of each AI request (the feature used, the AI provider and model, the amount of text processed, the time taken, the cost and whether it succeeded). These records do not contain your documents, prompts or AI outputs.
  • Server logs. Our hosting provider keeps our application logs. They may include usernames entered when signing in, file names, user IDs in some error messages and, when an error occurs, short excerpts of document text or AI output.
  • Cookies and similar technologies. See Section 11.

3.5 What we do not collect. We do not collect precise location, contacts, biometric data or identity documents, except where they appear in documents you upload. Please do not upload sensitive personal data unless your task needs it (see Section 7.5 of our Terms of Service).

3.6 What you must provide. To create an account, you need an email address, a username and a password, or an account with one of our sign-in providers. To buy a Paid Plan or a point pack, you need to give Stripe your payment details. Without them, we cannot provide those parts of the Service. Everything else is up to you.

4. How we use personal data, and our legal bases

The table below lists our purposes. Where a law that applies to us requires a legal basis for processing, the table also shows it.

PurposePersonal dataLegal basis
Create and manage your account, sign you in and link sign-in methodsAccount data; sign-in provider data; sign-in recordsPerformance of our contract with you
Verify your email address when you sign upEmail address; verification codeContract; our legitimate interest in preventing fake and abusive accounts
Provide the features you use, including sending Customer Content to our AI and document-processing providersAccount ID; Customer ContentFor your own account data: contract. For personal data in Customer Content, we act for the customer, which is responsible for the legal basis
Sell and manage Paid Plans and point packs; process payments, refunds and PointsName; email address; Stripe identifiers; plan; payment and Points historyContract; our legitimate interest in keeping accurate financial records and meeting the accounting and tax rules that apply to us; legal obligation where the law requires
Show the prices, sign-in options and version of our terms that apply in your regionIP address (not stored); countryLegitimate interest in showing you relevant prices and options
Keep the Service secure and prevent fraud and abuse — for example rate limiting, investigating misuse, and preventing abuse of free Points or refundsIP address; user ID; sign-in attempts in logs; Points and payment historyLegitimate interest in protecting the Service, our users and us
Diagnose and fix errorsServer logsLegitimate interest in running a reliable Service
Answer your questions and requests, including requests to exercise your rightsContact details; messages; account dataContract; legal obligation, where the law gives you these rights; legitimate interest
Send service messages — for example about changes to our terms, prices or providers, about renewals and receipts, and about securityEmail address; notices in the ServiceContract; legitimate interest in keeping you informed
Handle payment disputes and legal claimsUsage records; Points history; payment recordsLegitimate interest in establishing, exercising and defending legal claims
Comply with laws and respond to lawful requestsAs neededLegal obligation; legitimate interest
Produce statistics about the use and cost of the ServiceUsage records; AI request recordsLegitimate interest in operating and improving the Service
Reorganise, merge or sell our businessAs neededLegitimate interest

Where we rely on legitimate interests, we have weighed them against your rights, and you can object (Section 10).

We do not use personal data for advertising or to build marketing profiles, and we do not currently send marketing emails. If that changes, we will ask for your consent where the law requires it, and you will be able to opt out at any time.

5. How our AI Features process your content

5.1 What we send, and to whom. When you use an AI Feature, we send the content needed for that task — often the full text of a contract and, for PDF files, the whole file — to the providers below. They return the results to us, and we store the results in your account. We do not include your name, email address or account ID in these requests, but the documents themselves often contain personal data.

ProviderWhat it receivesWhyWhere it processes data
DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.)The full text of contracts you review and, for comparisons, the full text of the new version and the passages that changed; your messages to the drafting assistant and the deal details; text from files you upload for drafting or for extracting review rules; template text; your questions about a contract, with the relevant passages; your follow-up questions and background factsTo generate drafts, reviews, comparisons, answers and extracted rulesMainland China
Alibaba Cloud Model Studio (Alibaba Cloud (Singapore) Private Limited)The text of your templates, clauses and contracts, and your search queriesTo create embeddings for search and matchingSingapore
RegenAIWhole PDF files you upload for review, comparison or rule extraction, with their file namesTo convert PDF files into text and structureMainland China (according to RegenAI's public information)

5.2 Changes to these providers. We may switch AI or document-processing providers. Before we start sending Customer Content to a provider that is not listed here, we will update this policy and give notice as described in Section 8.4 of our Terms of Service.

5.3 Training and retention: what we, and our providers, have committed to.

  • DealMate does not use Customer Content to train or fine-tune AI models. We do not have AI models of our own.
  • DeepSeek. As of the effective date of this policy, the terms that govern DeepSeek's API service (the DeepSeek Open Platform Terms of Service) contain no commitment either way about using API data to train its models, and they do not say how long DeepSeek keeps API inputs and outputs. DeepSeek's separate statement on how it trains its models says that some training data may be based on user input, without saying whether this includes API requests. DeepSeek's documentation says that it caches request content on disk by default and clears unused cache, usually within a few hours to a few days. DeepSeek processes data in mainland China. We have not obtained any further data protection commitments from DeepSeek.
  • Alibaba Cloud states publicly that it never uses customer data from Model Studio to train models. It does not state how long it keeps request data.
  • RegenAI has not published terms on how long it keeps files or whether it uses them for any other purpose, and we have not obtained any data protection commitments from it.

Because of this, we cannot make promises on behalf of DeepSeek or RegenAI about how long they keep Customer Content or whether they use it to train models.

5.4 AI results. AI outputs can be wrong or incomplete (see Section 6 of our Terms of Service). They are suggestions for you to consider. We do not use AI to make decisions about individuals that have legal or similarly significant effects on them.

6. Who we share personal data with

6.1 Service providers. These providers process personal data for us, on our instructions, to run the Service.

ProviderWhat it does for usPersonal data involvedLocation
上海甄零科技有限公司 (Shanghai Zhenling Technology Co., Ltd.)Develops, operates, maintains and supports the Service for us, including answering your questions and requestsAll the data we store, accessed remotelyMainland China
Zeabur Inc. (a United States company)Hosts our application, database, cache and server logsAll the data we storeServers in Tokyo, Japan
Cloudflare, Inc. (United States)Stores the original files you upload (Cloudflare R2)Uploaded filesUnited States
DeepSeekAI processing (Section 5)Customer ContentMainland China
Alibaba Cloud (Singapore) Private Limited (Model Studio)Embeddings (Section 5)Customer ContentSingapore
RegenAIPDF parsing (Section 5)PDF files and file namesMainland China (according to RegenAI's public information)
Resend (United States)Sends the verification-code email when you sign upEmail address; verification codeUnited States

6.2 Independent companies. These companies receive or provide personal data for their own purposes, under their own privacy policies:

  • Stripe processes your payments. When you first buy something, we give Stripe your name, email address and account ID so that it can create your customer record; Stripe collects your card details and billing address directly. If you dispute a charge, we may give Stripe records of your use of the Service, including your Points history. See Stripe's privacy policy at https://stripe.com/privacy.
  • Google, Microsoft and Apple (United States) and Alipay (mainland China) handle sign-in when you choose them, and they learn that you are signing in to DealMate. If you sign in with Google, your browser loads your profile picture directly from Google, so Google can see your IP address and browser details when it does so.

6.3 Other disclosures. We may also disclose personal data:

  • to our professional advisers (such as lawyers, accountants and auditors), who owe us a duty of confidentiality;
  • to public authorities, courts or other parties where the law requires us to, or where needed to protect our rights, our users or others (see Section 7.3);
  • to a buyer or successor if we are involved in a merger, acquisition or sale of all or part of our business — we will tell you before your personal data becomes subject to a different privacy policy; and
  • to anyone else, with your permission or at your direction.

6.4 No selling. We do not sell personal data. We do not share it for cross-context behavioural advertising, or with third parties for their own marketing.

7. International transfers and access from mainland China

7.1 Where your personal data is processed.

  • Japan. Our application, database and server logs are hosted in Tokyo by Zeabur, a United States company.
  • Mainland China. Shanghai Zhenling, which develops, operates and supports the Service for us, is in mainland China; its personnel access personal data remotely to operate, support, maintain and secure the Service. DeepSeek processes Customer Content in mainland China. According to its public information, RegenAI is based in mainland China. If you sign in with Alipay, Alipay processes your sign-in in mainland China.
  • Singapore. Alibaba Cloud processes the data described in Section 5 in Singapore.
  • United States. Zeabur, Cloudflare (which stores the original files you upload), Resend, Stripe, Google, Microsoft and Apple are United States companies.

If you live outside these countries, your personal data is therefore transferred to them. Their laws may protect personal data less than the laws of your country.

7.2 How we protect transfers.

  • Your consent and instructions. When you sign up, we ask you to tick a checkbox confirming that you agree to this policy — including, expressly, that the content you upload is processed by AI providers in mainland China. For your own personal data, this is your consent to the transfers described in Section 7.1; where a law makes consent a basis for such transfers — for example, Japan's Act on the Protection of Personal Information (see Section 13.3) — we rely on it. For personal data about other people in Customer Content, it is your instruction to us as the customer; you remain responsible for having a lawful basis to upload that data (Section 2.2).
  • Where a provider offers data processing terms or standard contractual clauses, we use them.
  • DeepSeek and RegenAI have not agreed to such clauses or terms with us. Customer Content sent to them is protected only by their standard terms and by the law of mainland China. Zeabur, our hosting provider, does not publish data processing terms, and we have not yet signed any with it. Customers should take this into account when deciding what to upload (see Section 8.5 of our Terms of Service).
  • We send data to our AI and document-processing providers over encrypted (HTTPS) connections and without account identifiers (Section 5.1).
  • You can ask for a copy of the transfer safeguards we use by emailing cs@onecontract-cloud.com.

7.3 Government access and the law of mainland China. Because the people who operate the Service, and some of our providers, are in mainland China, the law of mainland China applies to data held there or accessed from there. That law — including the Cybersecurity Law, the Data Security Law and the National Intelligence Law — requires organisations and individuals to support and cooperate with state security and intelligence work, and gives the authorities broad powers to obtain data. The law of mainland China also requires approval from its authorities before data stored in mainland China is provided to foreign courts or law-enforcement authorities. When we receive a request for data from any public authority, we review it and disclose only what we are legally required to disclose. Where the law allows, we tell the affected customer.

7.4 Users in Japan. Section 13.3 contains the information required by Japan's Act on the Protection of Personal Information.

8. How long we keep personal data

DataHow long we keep it
Account data (email address, username, name, password hash, language) and sign-in recordsWhile your account is open; deleted within 30 days after your account is closed. The record of a sign-in method is deleted when you remove that method from your account
Records of your acceptance of our terms and policies, including your consent to automatic renewalWhile your account is open, and for 3 years after it is closed, so that we can show what you agreed to
Customer ContentUntil you delete it or your account is closed — see the notes below
Original files you uploadDeleted within 30 days after you delete the item they belong to, or after your account is closed. Files you upload as business materials while drafting are kept for up to 30 days (their text stays in your conversation). PDF files you start to upload for a comparison but do not confirm are deleted within 24 hours. Files you upload for a review are not stored as files
Billing records (payments, refunds and the related Points entries)As long as the accounting and tax laws that apply to us require, and as needed to handle disputes
Other Points history, and AI request recordsWhile your account is open
Server logsAt least six months, as the law that applies to us requires; we delete them when we no longer need them
BackupsOverwritten on a rolling basis; deleted data may remain in backups until it is overwritten
Rate-limiting data (IP address, user ID)Up to one hour
Email verification codesFive minutes, or until used
Sign-in flow records (one-time sign-in tickets, stored only as a hash; records used to hand over an Alipay sign-in from the Alipay app to your browser, including your browser's user-agent string)Expire after 60 seconds to five minutes, and are deleted within 7 days after they expire
Support emailsUp to two years after your request is resolved

Notes on Customer Content.

  • Deleting a contract also deletes its versions, its text sections and embeddings, and the reviews and comparisons linked to it.
  • Some related items are kept until you delete them separately: conversations (even after you delete a contract drafted from them); the two documents in a comparison (deleting a comparison deletes its results, but the documents stay in your contract list); and review rules (each rule keeps a copy of the clause text it was extracted from, even after the source contract is deleted).
  • If you discard a rule-extraction job, the files you uploaded for it and the text extracted from them are deleted within 30 days.
  • If you cannot delete an item yourself, email us and we will delete it.
  • We may keep specific data for longer where we need it to establish, exercise or defend legal claims, or where the law requires it.
  • Our AI and document-processing providers keep data as described in Section 5.3.

9. How we protect personal data

We use measures that we can verify, including:

  • Encryption in transit: connections between your browser and DealMate use HTTPS, and we connect to our AI and document-processing providers over HTTPS.
  • Password protection: we store passwords only as salted hashes (bcrypt).
  • Protected sessions: your sign-in session is kept in an encrypted cookie that scripts on the page cannot read.
  • Access controls: the Service checks that a signed-in user is allowed to access an item before returning it. Our personnel access Customer Content only when needed to troubleshoot a problem, handle your request or meet a legal obligation, and only to the extent necessary.
  • Abuse protection: we limit request rates, including for sign-up and verification codes.
  • Hosting security: our servers and file storage are run by our hosting and storage providers, which are responsible for the physical and infrastructure security of their facilities.

We do not currently hold security certifications such as ISO 27001 or SOC 2. No system is completely secure, and we cannot guarantee that personal data will never be accessed without authorisation. If a personal data breach affects you, we will notify you, and the relevant authorities, where the law requires.

10. Your rights

10.1 Your rights. Depending on where you live, you may have the right to:

  • access your personal data and get a copy of it;
  • correct inaccurate data;
  • have your data deleted, or your account closed;
  • restrict or object to our use of your data, including use based on our legitimate interests;
  • withdraw your consent, where we rely on consent;
  • not be treated differently because you exercised your rights; and
  • complain to a data protection authority (see Section 13).

10.2 What you can do yourself in the Service. You can view and delete contracts, reviews, comparisons, conversations, templates and clauses; export individual documents, comparison reports and review opinions; download original files you uploaded; see your Points and payment history; change your display name, email address, password and interface language; reset a forgotten password from the sign-in page; add or remove sign-in methods; cancel your subscription in the Stripe customer portal; and close your account.

10.3 Everything else, by email. We do not offer a feature or service that exports all your data, including Customer Content, in one go. This does not limit your right to access your personal data or ask us to disclose it. For those requests, and for anything else you cannot do yourself, email cs@onecontract-cloud.com from the email address linked to your account. If your account has no email address (for example, because you sign in only with Alipay), tell us your username and we will verify your identity in another way, such as by asking you to carry out a specific action while signed in to your account. We may ask for more information to confirm your identity. If you use an authorised agent, we may ask for proof of the agent's authority and confirm the request with you directly.

10.4 Timing and cost. We will respond within one month of receiving your request. If a request is complex, we may extend this by up to two further months where the law allows; if we do, we will tell you why. We do not charge for requests, unless a request is manifestly unfounded or excessive and the law allows a fee. For users in Japan, the timing in Section 13.3(d) applies.

10.5 Customer Content. For personal data in documents uploaded by one of our customers, see Section 2.3.

11. Cookies and similar technologies

We use only cookies and similar technologies that are needed to provide the Service or to remember your choices. We do not use advertising or analytics cookies, and we do not place third-party cookies or use third-party analytics or advertising scripts. For this reason we do not show a cookie consent banner. If we ever add cookies that require consent, we will ask for it first.

Cookies set by DealMate

CookiePurposeDuration
__Secure-authjs.session-tokenKeeps you signed in (encrypted)30 days
__Host-authjs.csrf-tokenProtects sign-in against cross-site request forgeryBrowser session
__Secure-authjs.callback-urlReturns you to the right page after you sign inBrowser session
__Secure-authjs.pkce.code_verifier, __Secure-authjs.state, __Secure-authjs.nonceSecure sign-in with Google, Microsoft or AppleUp to 15 minutes (nonce: browser session)
dm_pending_identityHolds a new sign-in identity while you confirm whether you already have an account10 minutes
dm_link_intentRemembers that you asked to link a sign-in method10 minutes
dm_alipay_stateSecures sign-in with Alipay10 minutes
dm_alipay_handoffLets your browser complete an Alipay sign-in that you approved in the Alipay app5 minutes
dm_login_ticketOne-time sign-in ticket60 seconds
dm_flashShows a one-time confirmation messageDeleted once shown
localeRemembers your interface language1 year
device_typeRemembers whether to show the mobile or desktop layout1 year
payment_regionRecords a pricing region for your visitBrowser session

Sign-in cookies (all of the above except locale, device_type and payment_region) cannot be read by scripts on the page and are sent only over HTTPS.

Local storage. We also use your browser's local storage and session storage to remember interface state on your device — for example, the conversation you are working on, tips and notices you have closed, clauses you have confirmed and the review depth you last chose. This information stays in your browser.

Other websites. Stripe, Google, Microsoft, Apple and Alipay set their own cookies on their own websites when you use them to pay or to sign in; see their policies.

You can delete or block cookies in your browser settings, but if you block the sign-in cookies you will not be able to sign in.

12. Children

DealMate is for business and professional use by people aged 18 or over. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe that a child has given us personal data, contact us and we will delete it.

13. Information for specific regions

13.1 European Economic Area, United Kingdom and Switzerland

The Service is not directed at people in these countries, and we do not market it there.

13.2 United States, including California

This section applies to residents of US states that have privacy laws, including California (the California Consumer Privacy Act, as amended). It supplements the rest of this policy.

Personal information we have collected in the past 12 months

CategoryExamplesSourcesPurposes (Section 4)Disclosed for a business purpose to
IdentifiersName, username, email address, account ID, sign-in provider IDs, IP addressYou; sign-in providers; your deviceAccount, Service, security, billingService providers (hosting, email delivery); Stripe
Customer recordsName, email address; billing details held by StripeYou; StripeBillingService providers (hosting); Stripe
Commercial informationPlans and purchases; Points historyYou; StripeBilling; security; disputesService providers (hosting); Stripe (for disputes)
Internet or other electronic network activityUsage records, server logs, device type, browser languageYour device; our systemsSecurity; fixing errors; statisticsService providers (hosting)
Geolocation dataThe country you connect from, derived from your IP address (not your precise location)Your deviceShowing regional prices and optionsNot disclosed
Sensitive personal informationAccount log-in (username or email address, with password)YouAccount access and security onlyService providers (hosting, which stores the password hash)

Customer Content is processed on behalf of our customers as their service provider (Section 2.2) and is not included in this table. We keep each category for the periods set out in Section 8.

No sale or sharing. We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. Because we do not sell or share personal information, there is nothing to opt out of, and a Global Privacy Control signal does not change how we process your data. We do not disclose personal information to third parties for their direct marketing purposes.

Sensitive personal information. We use it only to provide the Service and keep it secure — purposes that do not give rise to a right to limit its use.

Your rights. You may ask to know what personal information we have collected about you (including specific pieces of information), and to delete or correct it. We will not treat you differently for exercising these rights. Section 10.3 explains how to make a request. We will confirm receipt within 10 business days and respond within 45 days; if we need more time, we will tell you, and we may extend by up to 45 more days. An authorised agent may make a request for you with your written permission; we may ask you to verify your identity directly.

Other states. If you live in another state with a privacy law, you may have similar rights, including the right to opt out of targeted advertising, sale of personal data or profiling (we do none of these). We will respond to your request whether or not your state's law applies to us. If we decline your request, you may appeal by replying to our decision, and we will respond to your appeal within 45 days. If we deny your appeal, you may contact your state attorney general.

13.3 Japan

This section provides the information required by Japan's Act on the Protection of Personal Information (APPI).

(a) Business operator. InoAI Technology Co., Limited (Hong Kong). We will tell you our address and the name of our representative without delay on request (email cs@onecontract-cloud.com).

(b) Purposes of use. We use the retained personal data we hold (保有個人データ) for the purposes set out in Section 4.

(c) Personal data we handle for customers. Personal data in Customer Content is handled on behalf of our customers (entrustment, 委託). It is not our retained personal data, so requests about it should go to the customer; we will help the customer respond (Section 2.3). Business customers in Japan can use the information in paragraph (f) when entrusting personal data to us.

(d) Requests. You can ask us to notify you of the purposes for which we use your retained personal data; to disclose it (including records of its provision to third parties); to correct, add to or delete it; to stop using or to erase it; or to stop providing it to third parties. Email cs@onecontract-cloud.com; Section 10.3 explains how we verify your identity. We will respond without delay, and within one month, electronically unless you ask for another method that we can provide. We do not charge a fee.

(e) Security control measures.

  1. Basic policy. We have adopted this Privacy Policy as our basic policy on handling personal data, and we have set up a contact point for questions and complaints (cs@onecontract-cloud.com).
  2. Handling rules. We have internal rules for each stage of handling personal data — acquisition, use, storage, provision, deletion and disposal — that set out who is responsible and how the work is done.
  3. Organisational measures. We have appointed a person responsible for handling personal data, set up a process for reporting incidents and breaches of our rules, and review our handling of personal data regularly.
  4. Human measures. Our personnel are bound by confidentiality obligations and receive training on handling personal data.
  5. Physical measures. Our systems run in data centres operated by our hosting and storage providers, which are responsible for their physical security. We protect the devices our personnel use to access personal data against loss and theft.
  6. Technical measures. Access controls and authentication for systems that hold personal data; HTTPS encryption in transit; hashed passwords; encrypted session cookies; and request-rate limits.
  7. Understanding the external environment. We handle personal data in the countries listed in Section 7.1 and in paragraph (f), and we take security measures after understanding their systems for protecting personal information, as summarised in paragraph (f).

(f) Provision to third parties in foreign countries (APPI Article 28). We provide personal data to the recipients below, which are located outside Japan, with your consent. You give it when you sign up, by ticking a checkbox to agree to this policy after being shown this information (Section 7.2). We rely on that consent for all the recipients below, including DeepSeek and RegenAI, which have no contract with us ensuring measures equivalent to those required by the APPI.

RecipientCountry (server location)What we provide, and whyPersonal information protection system in that countryMeasures the recipient takes
上海甄零科技有限公司 (Shanghai Zhenling Technology Co., Ltd.)People's Republic of ChinaAll the data we store, accessed remotely to develop, operate and support the Service (Section 6.1)See note 1 belowHandles personal data on our behalf and on our instructions; its personnel are bound by confidentiality obligations (paragraph (e))
Hangzhou DeepSeek Artificial Intelligence Co., Ltd.People's Republic of China (servers in the People's Republic of China)Customer Content, for AI processing (Section 5)See note 1 belowNo contract with us that ensures measures equivalent to those required by the APPI. Its published terms contain no commitment on how long it keeps data or on not using data to train models (Section 5.3). Its other measures are therefore unknown to us
RegenAIPeople's Republic of China (according to RegenAI's public information)PDF files and file names, for parsing (Section 5)See note 1 belowNo contract with us that ensures measures equivalent to those required by the APPI, and no published terms on retention or data use. Its measures are therefore unknown to us
Alibaba Cloud (Singapore) Private Limited (Model Studio)SingaporeCustomer Content, for embeddings (Section 5)See note 3 belowWe use its service under its standard terms, under which it processes customer content on the customer's behalf. States publicly that it never uses Model Studio data to train models
Zeabur Inc.United States (servers in Japan)All the data we store, for hostingSee note 2 belowZeabur does not publish data processing terms, and we have not yet signed any with it
Cloudflare, Inc.United StatesUploaded files, for storageSee note 2 belowOffers a data processing addendum, including the Standard Contractual Clauses
ResendUnited StatesEmail address and verification code, for sending emailsSee note 2 belowOffers a data processing agreement
StripeUnited StatesName, email address and account ID; usage records if you dispute a chargeSee note 2 belowHandles payment data as an independent business under its own privacy policy

Note 1 — People's Republic of China. The PRC has a comprehensive personal information protection law (the Personal Information Protection Law, in force since 1 November 2021) that reflects the eight principles of the OECD Privacy Guidelines. It has no EU adequacy decision and does not take part in the APEC Cross-Border Privacy Rules (CBPR) system. Japan's Personal Information Protection Commission (PPC) identifies systems in the PRC that may significantly affect individuals' rights: data localisation requirements (under the Personal Information Protection Law, the Cybersecurity Law and the Data Security Law) and broad obligations to cooperate with government information-gathering (under the Cybersecurity Law, the Data Security Law and the National Intelligence Law), which the PPC notes lack clear limits, purpose restrictions, independent approval and transparency. See the PPC's report: https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_china/

Note 2 — United States. The United States has no comprehensive federal personal information protection law; sector-specific federal laws and state laws apply. The United States takes part in the APEC CBPR system. See the PPC's report: https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_america/

Note 3 — Singapore. Singapore has a comprehensive personal data protection law for the private sector (the Personal Data Protection Act 2012) and takes part in the APEC CBPR system. See the PPC's report: https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_singapore/

(g) Complaints. Please send complaints about how we handle personal data to cs@onecontract-cloud.com. You can also contact Japan's Personal Information Protection Commission (https://www.ppc.go.jp/).

13.4 Hong Kong

This section provides information required by the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong.

  • Purposes and recipients. We use personal data for the purposes in Section 4 and may transfer it to the classes of recipients in Sections 5 and 6.
  • Whether you must provide it. Section 3.6 explains which data you must provide and what happens if you do not.
  • Access and correction. You may ask for access to, and correction of, your personal data. Send your request to our Data Protection Officer (4/F, Building B, No. 33 Huilian Road, Qingpu District, Shanghai, People's Republic of China; email: cs@onecontract-cloud.com). We will respond within the time in Section 10.4, and in any case within the 40 days the Ordinance requires. The Ordinance allows a fee for a data access request that is not excessive; we currently do not charge one.
  • Complaints. You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (https://www.pcpd.org.hk/).

14. Changes to this policy

We may update this policy, and we will publish each new version with its effective date. If a change is material — for example, a new category of recipient, or a new country to which we transfer personal data — we will also tell you by email or in the Service at least 30 days before it takes effect, unless the law requires the change sooner. We will not use personal data or Customer Content that you have already given us in a materially different way without your consent.

15. Contact us

  • Company: InoAI Technology Co., Limited (Hong Kong)
  • Email: cs@onecontract-cloud.com
  • Data Protection Officer: 4/F, Building B, No. 33 Huilian Road, Qingpu District, Shanghai, People's Republic of China
© 2026 DealMate. All rights reserved.Terms of ServicePrivacy PolicyNotice for customers in JapanContact us: cs@onecontract-cloud.com
Powered by AI • Built for dealmakers
IP Geolocation by DB-IP