CreateX

Privacy Policy

CreateX Privacy Policy

Effective 2026-09-04 · Version 1.0

This Privacy Policy explains how CreateX AI (衍界人工智能科技, "we", "us") collects, uses, stores, shares and protects personal information when you use CreateX (app.createx-ai.hk, the "Service") and this website (createx-ai.hk), and the rights you have.

The Service is provided to business customers. Your organization (the "Customer") is the controller of the business data held in the Service; we process that data on the Customer's behalf. Your organization's own privacy policy and internal rules also apply to you.

If you do not agree with this policy, please stop using the Service. Continued use means you have read and understood it.

01Scope and roles

This policy covers every feature of the Service (chat and AI assistants, work and tasks, meetings, files, reports, org insights, automations, mail and the admin console) and this website.

The Customer's administrators create employee accounts and decide org structure, roles and feature switches; we process data on the Customer's instructions and under this policy. For the limited data we collect from website visitors, we act as the controller.

02Information we collect

We collect only what is needed to provide the Service, mainly:

  • Account information: name, work email, phone number, department, position and reporting line entered by your administrator; the avatar and preferences you set yourself.
  • Business content: conversations, tasks, schedules, meeting details, meeting recordings and transcripts, minutes, reports, files and their metadata that you create or that arise from your use of the Service.
  • Mail data: when you or your administrator connect a company mailbox, the mailbox connection credentials, message contents and attachments.
  • Third-party meeting platform data: when you authorize Zoom or Tencent Meeting, the authorization tokens and your platform user identifier returned by the platform, basic details of meetings you create through the Service (meeting ID, link, time) and the cloud transcript after a meeting ends.
  • Technical information: login IP address, browser type, access times, request and error logs, used for security and troubleshooting.
  • Usage information: number of AI calls, credits consumed and the model used, for Customer billing and usage reporting.

This website uses a single cookie to remember your language choice. It uses no advertising or behavioral tracking cookies.

03How we use information

  • To provide and maintain the Service, including letting your AI assistant look up and organize information within your permissions.
  • To generate AI content: the context needed for the current task is sent to a model provider to produce replies, minutes, task drafts and similar output. We never use your data to train or fine-tune models.
  • For authentication, access control, account security and abuse prevention.
  • For billing, usage metering and reconciliation as requested by the Customer.
  • To respond to support requests from you or the Customer.
  • To comply with applicable law and regulatory requirements.

04Third-party integrations (including Zoom and Tencent Meeting)

The Service can integrate with third-party platforms. An integration is enabled only after you or your administrator explicitly authorize it, and it requests only the minimum permissions needed for the feature.

  • Zoom: used to create Zoom meetings from the Service, read the details of meetings you created, and, after a meeting ends, retrieve the cloud recording transcript to generate minutes. We store the authorization tokens (encrypted), your Zoom user ID, the meeting ID and join link, and the transcript text. We do not join meetings on your behalf and do not read meetings or recordings unrelated to the Service.
  • Tencent Meeting: same purpose and data scope as above, through the Tencent Meeting open platform authorization APIs.
  • Company mailbox: reads messages and attachments through the connection you configure, to support mail triage and filing attachments.
  • Customer-built tools (MCP servers): configured by the Customer's administrators; the Service calls them only as authorized by the Customer.

You can disconnect Zoom or Tencent Meeting at any time under Settings › Meeting settings; the authorization tokens are deleted immediately. You can also revoke access from the platform's own app management page. When you uninstall the app from the Zoom App Marketplace, Zoom sends us a deauthorization notice and we delete the tokens and platform user identifier associated with that authorization within 10 days. Minutes already generated are the Customer's business records and are kept or deleted under section 5.

05Storage, retention and deletion

  • Transfers: to deliver the corresponding features, data is transferred only as necessary to our model, speech-recognition and third-party meeting platform providers, each of which is required to protect it to a standard no lower than this policy.
  • Retention: data is kept for the duration of the Customer's subscription; the Customer can delete or export its data at any time. After termination we delete all of the Customer's business data within 30 days, except where the law requires retention.
  • Backups: the database is backed up daily; backup copies are retained on a 7-day / 4-week / 6-month schedule and then automatically destroyed.
  • Meeting recordings: after transcription and minutes generation, raw recordings are retained or deleted according to the Customer's settings.

06Security measures

  • HTTPS (TLS) encryption for all traffic.
  • Data of different customers is isolated at the database layer by enforced row-level security policies.
  • Passwords are stored as salted argon2id hashes; login attempts are rate-limited.
  • Third-party tokens and connection credentials are stored with AES-256-GCM encryption and never displayed in plaintext.
  • Files are accessed through short-lived authorized links; files, meetings and tasks are visible only to their participants.
  • AI assistants inherit exactly your permissions, and every write action runs only after your confirmation.

No system can guarantee absolute security. If a security incident involving personal information occurs, we will notify the Customer and affected users as required by law.

07Your rights

Under applicable law (including the Hong Kong Personal Data (Privacy) Ordinance and, where applicable, the PRC Personal Information Protection Law and similar laws), you have the following rights regarding your personal information:

  • Access and copies: to see the personal information we hold about you and obtain a copy.
  • Correction: you can edit your profile under Settings; other information can be corrected on request through your administrator or us.
  • Deletion: to request deletion of your personal information; the Customer can delete employee accounts and related data from the admin console.
  • Withdrawal of authorization: to disconnect third-party integrations or withdraw other authorizations at any time.
  • Export: the Customer can request an export of its business data.
  • Complaint: to lodge a complaint with us or with a competent supervisory authority.

Because the Service is provisioned by the Customer for its employees, some requests are handled after confirmation by the Customer. We respond to requests within 30 days.

08Minors

The Service is intended for employees of business customers and not for minors. If we learn that we have collected a minor's personal information without the required guardian consent, we will delete it promptly.

09Changes to this policy

We may update this policy from time to time. For material changes we notify you in the Service or through your administrator and update the effective date at the top. Continued use of the Service after a change means you accept the updated policy.

Contact us

CreateX AI (衍界人工智能科技)

Privacy requests and complaints: contact@createx-ai.hk

We respond to requests within 30 days.