Somobai平台隐私政策
生效日期:2026‑08‑21
重要提示:Somobai平台仅面向合法存续的企业组织机构提供 API 技术服务,不对社会普通自然人个人开放注册使用。本隐私政策用于说明平台数据处理规则,与《Somobai平台企业服务协议》配套使用。
一、适用范围
本隐私政策适用于厦门闪企科技有限公司运营的Somobai平台全部 API 调度、令牌配额、算力路由相关服务。
本平台服务对象为企业组织机构客户;企业内部经办人员仅代表所属企业操作租户后台,不属于平台独立服务对象。本平台调度算法环节不会主动采集、存储、解析任何自然人个人敏感信息。
二、我们收集与使用的数据类型
为实现大模型令牌校验、算力调度、负载熔断、运维审计的服务目的,我们仅收集以下业务资源类运行指标,不属于自然人个人信息:
1. 企业租户标识、租户令牌配额、令牌消耗扣减记录;
2. API 请求元数据:请求时间、请求标识、预估令牌消耗量、接口 QPS、集群 CPU / 内存负载指标;
3. 运维审计日志:后台参数变更记录、人工干预调度操作记录。
明确说明:
①调度服务不采集、不接收、不解析客户提交的业务提示词、业务文本、生成内容;客户业务内容由企业客户自行管控;
②调度链路不会采集身份证、手机号、地理位置等自然人个人敏感信息;
③上述数据仅用于本平台内部服务运行、故障排查、安全审计,不会用于画像、个性化分析,不会向任何第三方共享、转让。
三、数据存储与地域
1. 全部业务资源数据、调度审计日志均存储于中国境内福建省厦门市云服务器,全部计算、存储操作均在境内完成,不存在任何数据跨境传输行为。
2. 调度相关审计、流水日志留存期限不少于 6 个月;业务配置数据在企业租户账号存续期间保存;租户注销后按法律法规要求完成清理。
3. 平台采用传输加密、数据库权限最小化、访问操作全程留痕等安全防护措施,防范数据泄露、篡改、丢失风险。
四、数据对外共享、转让、公开披露
1. 除下述法定情形外,我们不会向任何第三方共享、转让平台所掌握的业务资源类数据。
2. 仅在以下情形可以对外提供数据:
(1)获得对应企业组织机构客户书面同意;
(2)根据法律法规、监管机关、司法机关依法出具的正式文书要求予以提供;
(3)为保障平台、公众重大合法权益,在必要限度内提供。
五、企业客户行使权利的渠道
企业组织机构客户如对数据处理、令牌扣减、调度记录存在疑问或异议,可通过如下渠道提出:
1. 平台租户后台工单系统;
2. 商务联系邮箱:bd@somobai.com
我方收到企业客户的查询、异议申请后,5 个工作日内完成核查反馈,相关处置记录归档留存。
备注:因本平台调度环节不处理自然人个人信息,故不适用个人信息主体的查阅、删除、更正等个人权利场景。
六、安全防护措施
1. 技术层面:服务网络隔离、传输加密、最小账号权限、入侵检测、操作日志审计;定期漏洞扫描、压力测试。
2. 管理层面:建立数据安全管理制度,内部人员严格权限管控;调度策略、阈值变更执行评审审批流程,所有操作留痕可追溯。
七、未成年人保护
本平台仅向企业组织机构提供服务,不存在面向未成年人的个人账号,不收集未成年人相关信息。
八、本政策更新
我方有权根据法律法规、业务变更更新本隐私政策;更新版本将直接发布于本网页地址,不单独逐家通知。企业机构客户继续使用平台服务即视为知悉并接受更新后政策。
九、联系我们
如对本隐私政策有疑问,可发送邮件至:bd@somobai.com,主体单位:厦门闪企科技有限公司。
Somobai Platform Privacy Policy
Effective date: 2026‑08‑21
Important: The Somobai platform provides API technical services only to legally existing enterprises and organizations and is not open to registration or use by individual members of the public. This Privacy Policy describes how the platform processes data and should be read together with the Somobai Platform Enterprise Service Agreement.
1. Scope
This Privacy Policy applies to all API scheduling, token quota and compute routing services of the Somobai platform operated by Xiamen Shanqi Technology Co., Ltd..
The platform serves enterprise and organizational customers. A customer's employees operate the tenant console only on behalf of their organization and are not separate users of the platform. The platform's scheduling process does not proactively collect, store or parse any sensitive personal information of natural persons.
2. Data We Collect and How We Use It
To validate large-model tokens, schedule compute, apply load protection and support operational audit, we collect only the following operational resource metrics, which are not personal information of natural persons:
1. Tenant identifiers, tenant token quotas and token deduction records;
2. API request metadata: request time, request ID, estimated token consumption, API QPS, and cluster CPU / memory load metrics;
3. Operational audit logs: records of back-end configuration changes and manual scheduling interventions.
To be clear:
① The scheduling service does not collect, receive or parse the prompts, text or generated content submitted by customers; customers remain in control of their own business content;
② The scheduling pipeline does not collect sensitive personal information of natural persons such as ID numbers, phone numbers or location;
③ The above data is used solely to operate the platform, troubleshoot issues and perform security audits. It is not used for profiling or personalized analysis, and is not shared with or transferred to any third party.
3. Data Storage and Location
1. All operational resource data and scheduling audit logs are stored on cloud servers located in Xiamen, Fujian Province, within mainland China. All computation and storage take place within China, and no cross-border data transfer occurs.
2. Scheduling audit and transaction logs are retained for no less than six (6) months. Business configuration data is kept for as long as the tenant account exists and is deleted as required by applicable laws and regulations after the tenant account is closed.
3. The platform protects against data leakage, tampering and loss with measures including encryption in transit, least-privilege database access and full logging of access operations.
4. Sharing, Transfer and Public Disclosure
1. Except in the statutory circumstances below, we do not share or transfer the operational resource data held by the platform with any third party.
2. Data may be provided externally only:
(1) with the written consent of the relevant enterprise or organizational customer;
(2) where required by a formal document lawfully issued under laws and regulations or by a regulatory or judicial authority; or
(3) to the extent necessary to protect the significant legitimate rights and interests of the platform or the public.
5. How Enterprise Customers Can Exercise Their Rights
Enterprise and organizational customers with questions or objections about data processing, token deductions or scheduling records may contact us through:
1. the ticketing system in the tenant console;
2. our business contact email: bd@somobai.com
We will investigate and respond within five (5) business days of receiving an enterprise customer's inquiry or objection, and will archive the record of its handling.
Note: Because the platform's scheduling process does not handle personal information of natural persons, individual data-subject rights such as access, deletion and correction do not apply.
6. Security Measures
1. Technical: network isolation, encryption in transit, least-privilege accounts, intrusion detection and operation log auditing, plus regular vulnerability scanning and stress testing.
2. Organizational: a data security management policy and strict access control for internal staff; changes to scheduling policies and thresholds go through review and approval, and every operation is logged and traceable.
7. Protection of Minors
The platform serves only enterprises and organizations, offers no personal accounts to minors and does not collect information about minors.
8. Updates to This Policy
We may update this Privacy Policy in line with laws, regulations or changes to our business. Updated versions will be published directly at this web address without individual notice to each customer. Continued use of the platform by an enterprise or organizational customer constitutes acknowledgement and acceptance of the updated policy.
9. Contact Us
If you have any questions about this Privacy Policy, please email bd@somobai.com. Responsible entity: Xiamen Shanqi Technology Co., Ltd..