Alphora Group · Alphora Insights

隱私權政策 Privacy Policy

本政策依《個人資料保護法》及相關子法,就 Alphora Insights 個人資料蒐集、處理及利用之事項,依法告知。

版本:v6.5 | 生效日期:中華民國一百一十五年五月二十一日
發布主體:Alphora Group
客服信箱:info@alphoragroup.com
服務平台:https://insights.alphoragroup.com

第一條 適用範圍

本隱私權政策(下稱「本政策」)由 Alphora Group(下稱「本公司」)依據《個人資料保護法》(下稱「個資法」)及相關子法,就 Alphora Insights 平台(下稱「本平台」或「本服務」)個人資料蒐集、處理及利用之事項,依法告知。

本政策適用於使用者透過本網站、行動裝置或桌面應用程式存取本平台,進行帳號註冊、訂閱申請、使用人工智慧分析功能、金融數據查詢及與本公司客服人員溝通之所有情形。

本政策不適用於本平台超連結之第三方網站或應用程式。第三方之個人資料處理依各該第三方之隱私權政策自行規範,本公司對第三方之資料處理行為不承擔任何責任。

第二條 蒐集之個人資料類型

本公司依個資法規定,蒐集下列類型之個人資料:

第一項 基本識別資料

帳號登入識別符、電子郵件地址及帳號安全驗證資訊。使用者選擇以第三方帳號登入時,本公司將於使用者授權範圍內取得其電子郵件地址、顯示名稱及唯一帳號識別碼。

第二項 帳號設定及使用偏好資料

國籍、居住地、語言偏好設定、訂閱方案資訊、觀察清單、提醒條件、投資組合追蹤紀錄及執行通知狀態。

第三項 訂閱及帳務資料

訂閱狀態、方案類型、計費週期、付款事件元數據、發票資訊及爭議處理相關紀錄。本公司不自行儲存完整信用卡號碼、金融帳戶號碼或卡片驗證碼,相關支付資料由具備 PCI-DSS 合規認證之第三方付款處理商處理,詳見第五條。

第四項 人工智慧互動資料

使用者於人工智慧功能介面輸入之查詢指令及對話內容、系統回應紀錄及功能使用紀錄。使用者不得於人工智慧功能介面輸入金融帳號、身分證字號、護照號碼、個人健康資訊或商業機密;就違反前述限制所生之損害,本公司不承擔任何責任,相關責任完全由使用者自行承擔。

第五項 技術及設備資料

網際網路通訊協定位址(IP)、瀏覽器類型與版本、裝置類型與作業系統、連線時間戳記及系統日誌。

第六項 Cookie 及追蹤技術資料

依第十條規定辦理。

第七項 使用行為資料

頁面瀏覽紀錄、功能點擊路徑、搜尋查詢關鍵字、功能使用頻率、工作階段時長及錯誤日誌。

第八項 客服及溝通資料

使用者透過客服管道提交之問題說明、工單紀錄及使用者意見。

第九項 行為分析及統計推斷資料

本公司得以演算法,依使用者之使用行為資料,推斷使用者之興趣偏好、功能使用模式及服務滿意度,用於服務優化及功能改善。此類推斷資料以去識別化方式處理,不以可識別特定個人之方式使用。本公司不基於此類推斷資料進行任何形式之投資建議或金融顧問服務。

本公司明確排除蒐集種族、宗教、政治、性別偏好、個人健康記錄或任何個資法第六條所定特種個人資料,除使用者於客服溝通中主動提供外。

第三條 蒐集目的及法律依據

本公司蒐集、處理及利用個人資料,以下列目的為限:

  • 帳號建立與身分驗證、服務提供與維運、訂閱與帳務管理、AI 功能回應及使用者偏好資料儲存:法律依據為契約或類似契約關係(個資法第 19 條第 1 項第 2 款);
  • 平台安全監控、異常偵測、防範詐欺及不法行為、法令遵循、配合司法程序及主管機關要求:法律依據為法律明文規定(個資法第 19 條第 1 項第 1 款);
  • 以去識別化或匿名化資料進行服務效能分析、A/B 測試及內部研究:法律依據為公共利益或當事人同意(個資法第 19 條第 1 項第 6 款);
  • 行銷通訊(如本公司日後開展):以獨立明示勾選方式另行取得同意後始為之,並提供隨時撤回之機制。

本公司如擬另行處理上述目的以外之個人資料,將另行依個資法取得使用者之明示同意,並於取得同意後始為之。

第四條 第三方登入帳號資料

如使用者選擇以第三方帳號登入本服務,本公司得依該第三方之授權機制,取得使用者授權揭露之必要帳號資訊,包括電子郵件地址、顯示名稱及唯一識別碼,並僅於帳號建立、身分驗證、帳號連結、安全管理及存取控制等必要範圍內使用。本公司不出售該等資料,亦不將其用於廣告投放或行為追蹤目的。

第五條 付款處理及帳務資料保護

本公司委託具備 PCI-DSS 合規認證之第三方付款處理商,處理所有訂閱付款事務。使用者之完整信用卡號碼、金融帳戶號碼及卡片驗證碼等支付工具敏感資料,直接由該付款處理商之安全支付環境接收及處理;本公司伺服器不儲存、不記錄、不存取前述完整支付資料,因此本公司對支付資料之安全性不承擔任何責任。

本公司僅保留發票參考號碼、客戶識別符、付款狀態、訂閱方案狀態及計費週期等為提供服務所必要之帳務元數據。前述帳務元數據之保存期限,依本公司適用之稅務法規要求定之;如無法令強制規定,則保存期限不超過一年,期滿自動刪除或去識別化處理。

第三方付款處理商就其持有之付款資料,適用其本身之服務條款及隱私政策。本公司對付款處理商之行為,包含任何資料外洩事件,不負任何責任。

第六條 個人資料之提供與委外處理

本公司不出售、出租或以商業交換方式提供使用者個人資料予任何未經授權之第三方。本公司於蒐集目的必要範圍內,得提供、共享或委託處理使用者之個人資料,範圍限於下列對象:

  • 本公司員工及授權人員(限於執行職務所必要範圍,並依個資法負保密義務);
  • 雲端主機及基礎建設服務提供者(依資料處理協議提供服務,約定資料使用限制);
  • 身分驗證服務提供者(如 Google,僅限帳號登入及驗證之目的);
  • 付款處理服務提供者(僅限帳務管理及爭議處理所需之最小必要資料);
  • 人工智慧模型服務提供者(僅限提供本服務所必要之範圍,以去識別化或假名化方式處理);
  • 分析及監控服務提供者(以匿名化或假名化方式處理);
  • 客服支援平台(依資料最小化原則提供必要資料);
  • 法律、會計或其他專業顧問(於爭議處理或法律程序所必要範圍內);
  • 政府機關或執法單位(依法令規定、法院命令或主管機關要求,本公司有權不通知使用者即配合提供)。

受委託處理個人資料之第三方服務商,本公司將以契約方式明定保密義務及資料使用限制;惟本公司對受委託處理機構之行為不負任何連帶責任。

第七條 人工智慧資料處理政策

⚠ 本條係本政策對 AI 功能資料處理之核心條款,同時為本平台法律定性之重要依據,請使用者特別注意。
  • 使用者與本服務之互動資料,僅用於即時服務提供,及以去識別化或匿名化方式進行服務優化與分析,不得逾越前述範圍利用;超出範圍之利用將另行依個資法取得同意。
  • 人工智慧互動日誌之保存期限不超過三十日,期滿由系統自動刪除,法令另有規定者從其規定。
  • 本公司目前不以可識別個人身分之互動資料訓練或優化人工智慧模型。如本公司日後擬調整此政策,將事先以適當方式通知使用者,並依個資法取得明示同意後,僅對同意之使用者資料為之。
⚠ AI 輸出完全免責:本平台 AI 功能所產生之所有分析結果、報告及內容,均屬一般性參考資訊,絕對不構成任何形式之投資建議、財務建議、稅務建議或法律建議,不代表任何有價證券之買入或賣出推薦,不保證其完整性、即時性或正確性,亦不構成對市場走向、投資績效或任何財務結果之預測、保證或承諾。AI 生成內容可能存在錯誤、偏差、幻覺(hallucination)或與市場現實不符之情形,使用者不得以此作為投資決策之依據。
  • 使用者不得將人工智慧生成內容對外包裝或聲稱為投資建議、投資分析或任何形式之金融諮詢服務;違反前揭規定者,本公司得立即終止其帳號,並保留依法追償之完整權利。
  • 本公司不具備依《證券投資信託及顧問法》第四條經核准之證券投資顧問事業資格,亦不具備依《期貨交易法》第八十二條經核准之期貨顧問事業資格。

第八條 資料安全措施

本公司依個資法規定,建立個人資料安全維護計畫,就資料傳輸、儲存、存取控制、身分驗證、備份及委外管理等各面向,採行符合業界實務標準之合理安全措施,並指定個人資料保護負責人統籌相關事務。

網際網路傳輸及電子儲存方式無法保證絕對安全。如發生個人資料安全事件,且依法令規定須通知當事人者,本公司將於法令要求範圍內通知受影響之使用者。

就工程師自境外連線生產系統之安全管控,本公司依內部安全規範實施存取控制機制,並於個人資料安全維護計畫中具體記錄,以符合個資法第二十七條之安全維護義務。

第九條 個人資料保存期限

本公司各類個人資料及相關紀錄之保存期限依下列規定執行:

  • 人工智慧互動日誌:不超過三十日,期滿由系統自動刪除;
  • 客服溝通紀錄:保存一年,期滿自動刪除或去識別化;
  • 帳務元數據:依適用稅務法規要求保存,如無法令強制規定則不超過一年;
  • 使用行為數據(去識別化後):依服務優化需要保存,最長不超過三年;
  • 帳號資料:於帳號存續期間保存,帳號終止後依法令規定期間保存,法無規定者於終止後九十日內刪除或去識別化;
  • 其他資料:依各類資料性質及個資法等相關法令規定之期間保存。

就已逾保存期限、已依程序刪除,或因系統技術限制無法回復之資料,本公司不負提供、回復或重建之義務,亦不就此承擔任何賠償責任。

第十條 Cookie 及追蹤技術

本公司得使用各類追蹤技術以提升服務品質及營運效率,包括但不限於:

  • 第三方分析工具:用於記錄使用行為與功能使用情形,並可能透過 Cookie 辨識裝置;
  • 瀏覽器本地儲存機制(LocalStorage):用於保存登入狀態及使用者偏好設定;
  • 工作階段儲存機制(SessionStorage):用於處理登入驗證及暫存安全性資訊;
  • 行為分析追蹤:以匿名化或假名化方式記錄頁面互動,用於服務改善。

使用者使用本服務,即視為同意前述所有追蹤技術之使用,且不得因此對本公司主張任何損害賠償。本公司不提供個別調整或關閉機制,除法律另有強制規定外不在此限。本公司得依營運需要隨時調整前述技術之種類及用途;非重大技術性調整無需另行通知使用者。

第十一條 跨境資料傳輸

本公司得因提供服務之必要,依個資法第二十一條之規定,將個人資料傳輸予境外第三方處理,包含但不限於雲端服務提供者、AI 模型服務提供者及分析工具服務提供者。

使用者使用本服務,即視為知悉並不可撤回地同意本公司依前述情形進行跨境傳輸。本公司將以契約措施或其他適當安全機制保護跨境傳輸之個人資料;惟本公司對境外受託處理機構之資料保護水準不作任何保證,亦不就境外資料處理之損害承擔超出法定標準之責任。

第十二條 使用資格及聲明擔保

使用者使用本服務,即對本公司為下列不可撤回之聲明及保證:

  1. 具備完全行為能力,未受監護或輔助宣告;
  2. 年滿十八歲,且依中華民國法律或所在地法律具有完全行為能力;
  3. 未受任何法令、司法機關或主管機關限制使用本服務;
  4. 非屬國際制裁名單之個人或實體;
  5. 所提供之資料均為真實、正確且完整,且未含任何虛偽或誤導內容。

使用者違反前述任一聲明或保證者,本公司得不經通知逕行終止其帳號或限制服務使用,並保留依法請求完整損害賠償之權利。

第十三條 當事人權利

依個資法,使用者得就本公司保有之其個人資料,以書面方式(含電子郵件)向本公司行使下列權利:查詢或請求閱覽;請求製給複製本;請求補充或更正;請求停止蒐集、處理或利用;請求刪除。

本公司於個資法規定範圍內受理前述請求,並得依請求性質及範圍酌收必要之行政處理費用(約為新臺幣一千元至一千五百元或等值金額);於符合個資法第二十條第一項但書或其他法令規定之情形下,本公司得拒絕或限制相關請求,並依法說明理由。

就已逾保存期限或技術上無法回復之資料,本公司不負提供或回復之義務,亦不就此承擔任何賠償責任。使用者得隨時撤回就特定目的所為之同意,撤回同意不影響撤回前依法進行之資料處理行為之效力;撤回同意不產生任何費用退還義務。

第十四條 使用者賠償責任

使用者因下列情形致本公司或其全體受保護人員受有損害者,應負全額損害賠償責任,並應補償本公司因此所支出之律師費、訴訟費用、仲裁費用及其他一切合理費用:

  1. 違反本政策或本公司服務條款之任何規定;
  2. 從事任何違法或不當行為,包含但不限於詐欺、洗錢、侵害他人權利或違反法令強制規定;
  3. 不當使用本服務,包含但不限於濫用人工智慧功能、規避安全措施或干擾本服務正常運作;
  4. 提供不實、虛偽或誤導性資料,導致本公司或第三人受損;
  5. 因使用者之行為或不作為,致本公司遭主管機關裁罰、命令改正或涉及任何行政或司法程序;
  6. 違反第十二條使用資格及聲明擔保之任何規定;
  7. 任何源於使用者使用本服務而產生之第三人對本公司之索賠或請求。

第十五條 同意機制

使用者於註冊或使用本服務時,經點選或勾選同意,即視為已閱讀、理解並同意本政策及相關條款全部內容,並同意本公司依本政策蒐集、處理及利用其個人資料,該同意構成個資法所要求之有效同意,使用者不得事後以未充分閱讀為由主張同意無效。

就行銷通訊目的,本公司另以獨立勾選方式取得使用者之書面同意,與前項同意分別為之;使用者得隨時透過電子郵件取消訂閱或撤回該同意,撤回不影響撤回前已依法進行之資料處理行為之效力,撤回同意不產生任何費用退還義務。

第十六條 本政策之修訂與單方面更新權

⚠ 本公司保留隨時以任何理由、不須事先取得使用者同意,單方面修訂本政策之完全且不受限制之絕對權利。此項單方面更新權為本服務提供之核心條件,使用者於接受本政策時即知悉並不可撤回地同意此項安排。
  1. 本政策之修訂以於本公司官方網站公告為生效方式,不另以電子郵件逐一通知使用者。
  2. 涉及使用者重大權益或個人資料處理目的之實質性變更時,本公司得於網站首頁、登入頁面或其他適當位置公告,並至少於生效前五日顯示公告;如係配合法令要求之緊急修訂,本公司得不受前揭五日緩衝期限制。
  3. 修訂版本於公告所載日期起生效。使用者於修訂版本生效後繼續使用本服務,即不可撤回地視為已知悉、理解並全面同意修訂後之全部內容;如使用者不接受修訂後政策,唯一救濟方式為立即停止使用本服務,本公司不就帳號終止所生損失承擔任何責任。

第十七條 通知方式

本公司對使用者之通知,得以網站公告、服務頁面顯示、登入提示(包含但不限於彈出視窗)或其他適當數位方式為之,並於發出時視為已合法送達。本公司不另以電子郵件為通知義務之唯一履行方式;使用者不得以未實際收受通知為由否認通知之效力。

第十八條 條款效力可分性

本政策任一條款或其任何部分,因任何原因被認定為無效、不合法或不可執行者,不影響本政策其餘條款之效力,其餘條款仍繼續完全有效。

第十九條 條款存續

本政策中性質上於服務終止後仍應持續有效之條款,包含但不限於第七條(AI 資料處理及免責)、第十四條(使用者賠償責任)、第十八條(可分性)及第二十條(準據法與管轄),於服務關係終止後仍持續有效,不因任何原因而失效。

第二十條 準據法與管轄

本政策之成立、效力、解釋及履行,及因本政策或本服務所生之任何爭議,均以中華民國法律為排他性準據法,排除法律衝突原則之適用。因本政策或本服務所生之任何爭議,雙方不可撤回地合意以臺灣臺北地方法院為第一審專屬管轄法院,完全排除其他法院之管轄權,但法律另有強制規定者從其規定。

第二十一條 語言版本

本政策以中文(繁體中文)版本為正式且唯一具法律效力之版本;如有其他語言版本,僅供參考,如有任何歧義或衝突,以中文版本為最終依據。

第二十二條 聯絡方式

就個人資料相關事項、當事人權利行使及帳務詢問,得以書面方式(包含電子郵件)向本公司提出:

Alphora Group · Alphora Insights

Privacy Policy

Personal Data Protection Notice issued under the Personal Data Protection Act of the Republic of China (Taiwan), governing the collection, processing, and use of personal data by Alphora Insights.

Version: v6.5 | Effective Date: May 21, 2026
Issued by: Alphora Group
Contact: info@alphoragroup.com
Service Platform: https://insights.alphoragroup.com

Article 1. Scope of Application

This Privacy Policy (hereinafter "this Policy") is issued by Alphora Group (hereinafter "the Company," "we," "us," or "our") pursuant to the Personal Data Protection Act (hereinafter "PDPA") of the Republic of China (Taiwan) and its implementing regulations, to provide legally required notice regarding the collection, processing, and use of personal data in connection with the Alphora Insights platform (hereinafter "the Platform" or "the Service").

This Policy applies to all circumstances in which a user accesses the Platform via the website, mobile device, or desktop application to complete account registration, apply for a subscription, use AI-powered analytics features, query financial data, or communicate with the Company's customer service personnel.

This Policy does not apply to third-party websites or applications accessible via hyperlinks from the Platform. Each third party's processing of personal data is governed exclusively by its own privacy policy. The Company bears no responsibility for any third party's data processing activities.

Article 2. Categories of Personal Data Collected

The Company collects the following categories of personal data in accordance with the PDPA:

Item 1 — Basic Identifying Information

Account login identifiers, email addresses, and account security verification information. Where a user chooses to log in using a third-party account, the Company will obtain, within the scope of user authorization, the user's email address, display name, and unique account identifier.

Item 2 — Account Settings and Usage Preference Data

Nationality, place of residence, language preference settings, subscription plan information, watchlists, alert conditions, portfolio tracking records, and notification execution status.

Item 3 — Subscription and Billing Data

Subscription status, plan type, billing cycle, payment event metadata, invoice information, and dispute-related records. The Company does not independently store complete credit card numbers, financial account numbers, or card verification codes. Such payment instrument sensitive data is processed directly by a PCI-DSS-compliant third-party payment processor, as described in Article 5.

Item 4 — AI Interaction Data

Query commands and conversation content entered by users in the AI features interface, system response records, and feature usage records. Users must not enter financial account numbers, national identification numbers, passport numbers, personal health information, or trade secrets into the AI interface. The Company bears no liability for any damages arising from a user's violation of this restriction; all such liability is borne entirely by the user.

Item 5 — Technical and Device Data

Internet Protocol (IP) addresses, browser type and version, device type and operating system, connection timestamps, and system logs.

Item 6 — Cookie and Tracking Technology Data

As governed by Article 10 of this Policy.

Item 7 — Usage Behavioral Data

Page browsing records, feature click paths, search query keywords, feature usage frequency, session duration, and error logs.

Item 8 — Customer Service and Communications Data

Issue descriptions, ticket records, and user feedback submitted through customer service channels.

Item 9 — Behavioral Analytics and Statistical Inference Data

The Company may use algorithms to infer user interest preferences, feature usage patterns, and service satisfaction from user behavioral data, for the purposes of service optimization and feature improvement. Such inferred data is processed in de-identified form and is not used in a manner that identifies specific individuals. The Company does not use such inferred data to provide any form of investment advice or financial advisory services.

The Company expressly does not collect race, religion, political affiliation, sexual orientation, personal health records, or any special categories of personal data under Article 6 of the PDPA, except where a user voluntarily provides such information through customer service communications.

Article 3. Purposes and Legal Basis for Collection

The Company collects, processes, and uses personal data exclusively for the following purposes:

  • Account creation and identity verification, service provision and operations, subscription and billing management, AI feature responses, and storage of user preference data: Legal basis is a contractual or quasi-contractual relationship (PDPA Article 19, Paragraph 1, Subparagraph 2);
  • Platform security monitoring, anomaly detection, fraud and misconduct prevention, regulatory compliance, cooperation with judicial proceedings, and regulatory authority requirements: Legal basis is explicit statutory provision (PDPA Article 19, Paragraph 1, Subparagraph 1);
  • Service performance analysis, A/B testing, and internal research using de-identified or anonymized data: Legal basis is public interest or data subject's consent (PDPA Article 19, Paragraph 1, Subparagraph 6);
  • Marketing communications (if the Company develops such activities): To be conducted only after obtaining affirmative opt-in consent through a separate, independent checkbox, with a mechanism for withdrawal at any time.

If the Company intends to process personal data for purposes other than those listed above, it will first obtain the user's explicit consent in accordance with the PDPA, and will proceed only after such consent is obtained.

Article 4. Third-Party Login Account Data

Where a user chooses to log in to the Service using a third-party account, the Company may obtain, through the applicable third-party authorization mechanism, the account information the user authorizes for disclosure, including email address, display name, and unique identifier. Such data is used solely for account creation, identity verification, account linking, security management, and access control. The Company does not sell such data and does not use it for advertising targeting or behavioral tracking purposes.

Article 5. Payment Processing and Billing Data Protection

The Company engages a PCI-DSS-compliant third-party payment processor to handle all subscription payment transactions. Complete credit card numbers, financial account numbers, and card verification codes are received and processed directly by the payment processor's secure payment environment; the Company's servers do not store, log, or access such complete payment data. Accordingly, the Company bears no liability for the security of payment data.

The Company retains only the billing metadata necessary to provide the Service, including invoice reference numbers, customer identifiers, payment status, subscription plan status, and billing cycle information. The retention period for such billing metadata is determined by applicable tax law requirements; if no mandatory legal provision applies, the retention period shall not exceed one (1) year, after which the data is automatically deleted or de-identified.

The third-party payment processor's handling of payment data is subject to its own terms of service and privacy policy. The Company bears no liability for any action of the payment processor, including any data breach event.

Article 6. Disclosure and Delegation of Personal Data Processing

The Company does not sell, rent, or exchange users' personal data with any unauthorized third party for commercial purposes. Within the scope necessary for the purposes of collection, the Company may provide, share, or delegate the processing of personal data to the following recipients only:

  • The Company's employees and authorized personnel (limited to what is necessary for the performance of their duties, subject to confidentiality obligations under the PDPA);
  • Cloud hosting and infrastructure service providers (providing services under data processing agreements that specify data use restrictions);
  • Identity verification service providers (e.g., Google, solely for account login and verification purposes);
  • Payment processing service providers (solely for the minimum data necessary for billing management and dispute resolution);
  • AI model service providers (limited to what is necessary to provide the Service, processed in de-identified or pseudonymized form);
  • Analytics and monitoring service providers (processed in anonymized or pseudonymized form);
  • Customer support platforms (providing only the minimum necessary data in accordance with the principle of data minimization);
  • Legal, accounting, or other professional advisors (to the extent necessary for dispute resolution or legal proceedings);
  • Government authorities or law enforcement (pursuant to statutory provisions, court orders, or regulatory authority requirements; the Company is entitled to cooperate without notifying the user).

The Company will contractually require third-party service providers entrusted with processing personal data to comply with confidentiality obligations and data use restrictions; however, the Company bears no joint liability for the acts of such service providers.

Article 7. AI Data Processing Policy

⚠ This Article is the core provision of this Policy governing AI feature data processing and is an important basis for the legal characterization of the Platform. Please read carefully.
  • User interaction data with the Service is used solely for real-time service provision and for service optimization and analysis in de-identified or anonymized form. Use beyond the foregoing purposes shall require additional consent in accordance with the PDPA.
  • AI interaction logs are retained for no more than thirty (30) days and are automatically deleted upon expiration, unless otherwise required by applicable law.
  • The Company currently does not use personally identifiable interaction data to train or optimize AI models. If the Company intends to change this practice in the future, it will notify users in advance through appropriate means, and will proceed only with the data of users who have given explicit consent in accordance with the PDPA.
⚠ Complete disclaimer regarding AI outputs: All analytical results, reports, and content generated by the Platform's AI features constitute general informational content only. They do not constitute investment advice, financial advice, tax advice, or legal advice of any kind. They do not represent a recommendation to buy or sell any securities. They do not constitute investment advisory or futures advisory services. They do not guarantee completeness, timeliness, or accuracy. They do not constitute a prediction, guarantee, or commitment regarding market movements, investment performance, or any financial outcome. AI-generated content may contain errors, biases, hallucinations, or may not correspond to current market realities. You may not use AI-generated content as the basis for any investment decision.
  • You may not present or market AI-Generated Content as investment advice, investment analysis, or any form of financial consulting services. Violations will entitle the Company to immediately terminate your Account and to pursue all available legal remedies.
  • The Company does not hold a Securities Investment Advisory Enterprise license under Article 4 of the Securities Investment Trust and Consulting Act, nor a Futures Advisory Enterprise license under Article 82 of the Futures Trading Act. No AI feature output changes this legal characterization.

Article 8. Data Security Measures

Pursuant to the PDPA, the Company has established a Personal Data Security Maintenance Plan and has implemented reasonable security measures consistent with industry best practices across all aspects of data transmission, storage, access control, identity verification, backup, and third-party management. The Company has designated a Personal Data Protection Officer to oversee related matters.

Internet transmission and electronic storage methods cannot guarantee absolute security. In the event of a personal data security incident that, pursuant to applicable law, requires notification to affected individuals, the Company will notify affected users to the extent required by applicable law.

Regarding security controls for engineers accessing production systems from abroad, the Company implements access control mechanisms in accordance with its internal security policies, which are specifically documented in the Company's Personal Data Security Maintenance Plan in compliance with Article 27 of the PDPA.

Article 9. Personal Data Retention Periods

Retention periods for the Company's various categories of personal data and related records are as follows:

  • AI interaction logs: No more than thirty (30) days; automatically deleted upon expiration;
  • Customer service communications records: Retained for one (1) year; automatically deleted or de-identified upon expiration;
  • Billing metadata: Retained as required by applicable tax law; if no mandatory legal provision applies, no more than one (1) year;
  • Usage behavioral data (following de-identification): Retained as needed for service optimization, for a maximum of three (3) years;
  • Account data: Retained throughout the term of Account existence; following Account termination, retained for the period required by applicable law; if no legal provision mandates retention, deleted or de-identified within ninety (90) days of termination;
  • Other data: Retained for the period required by the nature of the data and applicable law.

The Company has no obligation to provide, restore, or reconstruct data that has exceeded its retention period, has been deleted pursuant to applicable procedures, or is technically irrecoverable due to system constraints. The Company bears no liability for such data.

Article 10. Cookies and Tracking Technologies

The Company may use various tracking technologies to improve service quality and operational efficiency, including but not limited to:

  • Third-party analytics tools: Used to record usage behavior and feature usage, and may identify devices through cookies;
  • Browser local storage (LocalStorage): Used to store login status and user preference settings;
  • Session storage (SessionStorage): Used to handle login authentication and temporarily store security information;
  • Behavioral analytics tracking: Records page interactions in anonymized or pseudonymized form for service improvement.

Your use of the Service constitutes your consent to the use of all of the foregoing tracking technologies, and you may not assert any claim for damages against the Company in connection with such use. The Company does not provide individual opt-out mechanisms, except as required by applicable law. The Company may adjust the types and purposes of such technologies at any time based on operational needs. Non-material technical adjustments do not require user notification.

Article 11. Cross-Border Data Transfers

The Company may, as necessary for the provision of the Service and pursuant to Article 21 of the PDPA, transfer personal data to overseas third parties for processing, including but not limited to cloud service providers, AI model service providers, and analytics tool service providers.

Your use of the Service constitutes your irrevocable knowledge of and consent to the Company's cross-border transfers described herein. The Company will protect personal data transferred across borders through contractual measures or other appropriate security mechanisms. However, the Company makes no warranty regarding the data protection standards of overseas processing entities, and bears no liability for losses arising from overseas data processing beyond the statutory standard of care.

Article 12. User Eligibility and Representations and Warranties

By using the Service, you make the following irrevocable representations and warranties to the Company:

  1. You have full legal capacity and have not been subject to a declaration of guardianship or assistantship;
  2. You are at least eighteen (18) years of age and have full legal capacity under the laws of the Republic of China (Taiwan) or your jurisdiction;
  3. You are not subject to any legal, judicial, or regulatory restriction from using the Service;
  4. You are not an individual or entity on any international sanctions list;
  5. All information you provide is true, accurate, and complete, and does not contain any false or misleading content.

If you breach any of the foregoing representations or warranties, the Company may immediately terminate your Account or restrict your use of the Service without notice, and reserves the right to seek full damages under applicable law. All legal liabilities and losses arising from use of the Service by an ineligible user shall be borne entirely by such user; the Company bears no joint, supplementary, or other liability.

Article 13. Data Subject Rights

Pursuant to the PDPA, you may exercise the following rights with respect to your personal data held by the Company by submitting a written request (including email) to the Company:

  • To inquire or request access;
  • To request a copy;
  • To request supplementation or correction;
  • To request cessation of collection, processing, or use;
  • To request deletion.

The Company will process requests within the scope required by the PDPA and may charge a reasonable administrative fee (approximately NTD 1,000 to 1,500, or equivalent). The Company may refuse or limit requests in circumstances permissible under Article 20, Paragraph 1, proviso of the PDPA or other applicable law, and will provide a legally compliant explanation for any such refusal.

The Company has no obligation to provide, restore, or reconstruct data that has exceeded its retention period or is technically irrecoverable, and bears no liability therefor. You may withdraw your consent to any specific purpose at any time. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal, and does not give rise to any obligation to refund fees.

Article 14. User Indemnification Obligations

You shall fully indemnify, defend, and hold harmless the Company and all Protected Persons from and against any damages, and shall reimburse the Company for all attorneys' fees, litigation costs, arbitration costs, and other reasonable expenses incurred, in connection with any of the following:

  1. Your breach of any provision of this Policy or the Company's Terms of Service;
  2. Any unlawful or improper conduct, including but not limited to fraud, money laundering, or infringement of third-party rights;
  3. Improper use of the Service, including but not limited to misuse of AI features or circumvention of security measures;
  4. Providing false, fraudulent, or misleading information causing harm to the Company or any third party;
  5. Any act or omission by you resulting in the Company being subject to regulatory penalties, corrective orders, or judicial or administrative proceedings;
  6. Your breach of any representation or warranty set forth in Article 12;
  7. Any third-party claim against the Company arising from your use of the Service.

Article 15. Consent Mechanism

By clicking to agree or checking the consent box during registration or use of the Service, you acknowledge that you have read, understood, and agreed to this Policy and all related terms in their entirety, and you consent to the Company's collection, processing, and use of your personal data in accordance with this Policy. This consent constitutes valid consent as required by the PDPA. You may not subsequently assert that your consent is invalid on the grounds of insufficient review.

For marketing communications purposes, the Company obtains your written consent through a separate independent checkbox, distinct from the foregoing consent. You may unsubscribe or withdraw such consent at any time by email. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal and does not give rise to any obligation to refund fees.

Article 16. Amendments to This Policy; Unilateral Amendment Right

⚠ The Company reserves the complete, unrestricted, and absolute unilateral right to amend this Policy at any time, for any reason, without obtaining your prior consent. This unilateral amendment right is a fundamental condition of the provision of the Service, and by accepting this Policy, you irrevocably acknowledge and agree to this arrangement.
  1. Amendments to this Policy take effect upon publication on the Company's official website. The Company is not obligated to notify each user individually by email.
  2. For material changes to your substantive rights or the purposes for which personal data is processed, the Company may post a notice on the website homepage, login page, or other appropriate location, displayed for at least five (5) days prior to the effective date. Emergency amendments required for regulatory compliance may take effect immediately without the five-day notice period.
  3. The amended Policy takes effect on the date indicated in the publication. Your continued use of the Service following the effective date constitutes your irrevocable knowledge of, understanding of, and full consent to the amended Policy in its entirety. If you do not accept the amended Policy, your sole remedy is to immediately cease using the Service. The Company bears no liability for any losses arising from Account termination.

Article 17. Notice

Notices from the Company to you may be delivered by website publication, service page display, login prompts (including but not limited to pop-up windows), or other appropriate digital means, and shall be deemed validly delivered upon dispatch. The Company is not obligated to use email as the sole means of notification. You may not deny the effectiveness of any notice on the grounds that you did not actually receive it.

Article 18. Severability

If any provision of this Policy or any portion thereof is held to be invalid, unlawful, or unenforceable for any reason, such invalidity shall not affect the remaining provisions of this Policy, which shall continue in full force and effect.

Article 19. Survival

Provisions of this Policy that by their nature should survive termination of the Service, including but not limited to Article 7 (AI Data Processing and Disclaimer), Article 14 (User Indemnification Obligations), Article 18 (Severability), and Article 20 (Governing Law and Jurisdiction), shall continue in full force and effect following termination of the service relationship and shall not be extinguished for any reason.

Article 20. Governing Law and Jurisdiction

This Policy shall be governed exclusively by the laws of the Republic of China (Taiwan), to the exclusion of any conflict of laws principles. Any dispute arising out of or in connection with this Policy or the Service shall be submitted exclusively to the Taiwan Taipei District Court as the court of first instance, with all other courts' jurisdiction fully excluded, except as otherwise required by applicable mandatory law.

Article 21. Language

The Chinese (Traditional Chinese) version of this Policy is the official and sole legally authoritative version. Any versions in other languages are for reference only. In the event of any ambiguity or conflict, the Chinese version shall be the final determinative authority.

Article 22. Contact Information

For matters relating to personal data, exercise of data subject rights, and billing inquiries, please submit a written request (including email) to: