Privacy Policy regarding the data processing connected to the Website
VerbaLink Europe Korlátolt Felelősségű Társaság (registered office: 1112 Budapest, Gulyás utca 24/1.; company registration number: 01-09-418897; hereinafter: “Data Controller”; “Verbalink” or “We”) as data controller processes the data of visitors to the website https://global.xfyun.com; hereinafter: “Website”) and guarantees the security of such data in accordance with this privacy policy (hereinafter: “Policy”), pursuant to the General Data Protection Regulation 2016/679 of the European Union (hereinafter: “GDPR”). Unless otherwise indicated in this Policy, the Data Controller shall collect your personal data directly from you and shall not obtain them from third parties.
This Privacy Policy only applies to this website and the products or services offered by the Data Controller via the website.
Last modified: 2023.11.27
Effective date: 2023.11.27
VerbaLink understands the importance of personal data to you and will do our utmost to protect your personal data. We are committed to maintaining your trust in us and abide by the following principles to protect your personal data: consistency of powers and responsibilities, clear objectives, choice and consent, least enough, ensuring security, subject participation, openness and transparency, etc. At the same time, VerbaLink undertakes that we will take appropriate security measures to protect your personal data in accordance with the mature industrial security standards and the provisions of the GDPR. Please read and understand this Privacy Policy carefully before using our products (or services), and confirm to understand our rules on the processing of your personal data. Once you click to confirm acceptance of this Privacy Policy or after the Privacy Policy is updated, your continued use of this software means that you acknowledge and accept all the contents of this Privacy Policy (including the updated version), and agree that VerbaLink will collect, use, save, share, transfer or disclose your relevant personal data.
This Privacy Policy will help you understand the following:
I. Definition and interpretation
II. How and why we collect and use your personal data
III. How we entrust to share, transfer and publicly disclose your personal data
IV. How we store and protect your personal data
V. Your rights
VI. How we handle minors' personal information
VII. How this Privacy Policy is updated
VIII. Contact us
I. Definition and Interpretation
I.1. Personal data
Personal data refers to all kinds of data recorded by electronic or other methods that can identify a natural person’s identity alone or in combination with other data, including but not limited to the natural person ’s name, date of birth, ID number, personal biometric data, address and telephone number.
I.2. Data processing
Data processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available,
I.3. Data subject
The term of data subject refers to the identified or directly/indirectly identifiable natural person.
I.4. Data Controller
Data controller means any natural or legal person, public authority, agency or other body which, alone or jointly with others, who determines the purposes and means of the processing of personal data.
I.5. Anonymization
Anonymization refers to the process during which personal data is subject to technical processing so that it is impossible to identify the subject of personal data and the processed data cannot be recovered.
I.6. Consent
Processing personal data is generally prohibited, unless it is expressly allowed by law, or is carried out based on one of the other possible legal bases set out in the GDPR. Consent is one of the six legal bases mentioned in the GDPR. The others are: contract, legal obligations, vital interests of the data subject, public interest and legitimate interest of the data controller. Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
II. How and why we collect and use your personal data
The Website collects and uses your personal data for the purposes described below in accordance with the principles of lawfulness, legitimacy and necessity.
We process the following personal data:
II. 1. Data provided for registering your account
Purpose of the data processing: | The registration (and so the data processing) is the precondition to use the services of the Website |
---|---|
Legal basis: | The consent of the data subject (see: Article 6(1) point a) of the GDPR) |
Data retention period: | The Data Controller will store and process the data subject’s personal data until the existence of the registration. |
Processed personal data: | e-mail address; country/region; account password, verification number |
Other relevant circumstances: | The data subject may withdraw his or her consent to the data processing at any time. Withdrawing the consent will not affect the lawfulness of processing based on consent before the withdrawal. |
II. 2. Voice, text, and image information that you submit when you experience and access abilities
Purpose of the data processing: | Provide Short Form ASR (Automated Speech Recognition) Service, Long Form ASR (Automated Speech Recognition) Service, TTS (Text to Speech) Service, Machine translation service, OCR (Optical Character Recognition) for users to experience and access |
---|---|
Legal basis: | The consent of the data subject (see: Article 6(1) point a) of the GDPR) |
Data retention period: | Stored untill the experience and access activities are completed. The data subject may withdraw his or her consent to the data processing at any time, when the consent is withdrawn, the data will be deleted. |
Processed personal data: | Voice, text, and image information (see: table II. 2.①-⑤ for details of personal data processed in various services) |
Data processors: | Cantab Research Limited (trading as "Speechmatics") and its server supplier in Ireland,United States Of America,provide Short Form ASR (Automated Speech Recognition) Service,Long Form ASR (Automated Speech Recognition) Service in some languages (https://www.speechmatics.com/legal/privacy-policy). |
(1)Short Form ASR (Automated Speech Recognition) Service
In order to ensure the security of your account and better provide you with high-quality services, we will collect and use the information generated by your use of Verbalink open platform short-term ASR services. Based on different devices, systems and versions, as well as the permissions determined by developers when integrating and using our products and/or services.
Types | Details of personal information | Processing purposes |
---|---|---|
Voice | Audio | Provide online speech to text service after voice input. |
Log information | Your detailed usage of the Verbalink Open Platform, including your product service usage record, search and query content, visited page address, browser type, network status, operator, language used, access date and time, system Records of activities and web pages you visit. We will also collect logs from your device to our API. | Improve and optimize product experience, and ensure service stability and network security through data statistics. Also it helps us to solve the issues that end users encounter when using the Online ASR API. |
Text | Text | The text message that is returned after recognition. |
Equipment information | Device ID (IMEI number), device code (IMSI code), IP address, Android ID (Android unique device ID to provide competency authorization services), OAID (Android devices only), IDFA (iOS devices only), OpenUDID (iOS devices only), and application. | As a means of authorized billing and user identification; At the same time, this information will also be used to more accurately locate and solve the problems encountered by developers and end users when using our products and/or services, and avoid conflicts with other applications, so as to provide you with better products and services. |
(2)Long Form ASR (Automated Speech Recognition) Service
In order to ensure the security of your account and better provide you with high-quality services, we will collect and use the information generated by your use of Verbalink open platform long form ASR services. Based on different devices, systems and versions, as well as the permissions determined by developers when integrating and using our products and/or services.
Types | Details of personal information | Processing purposes |
---|---|---|
Voice | Audio | Provide online Long form ASR (Automated speech recognition)service after voice input. |
Log information | Your detailed usage of the Verbalink Open Platform, including your product service usage record, search and query content, visited page address, browser type, network status, operator, language used, access date and time, system Records of activities and web pages you visit. We will also collect logs from your device to our API. | Improve and optimize product experience, and ensure service stability and network security through data statistics. Also it helps us to solve the issues that end users encounter when using the Online ASR API. |
Text | Text | The text message that is returned after recognition. |
Equipment information | Device ID (IMEI number), device code (IMSI code), IP address, Android ID (Android unique device ID to provide competency authorization services), OAID (Android devices only), IDFA (iOS devices only), OpenUDID (iOS devices only), and application. | As a means of authorized billing and user identification; At the same time, this information will also be used to more accurately locate and solve the problems encountered by developers and end users when using our products and/or services, and avoid conflicts with other applications, so as to provide you with better products and services. |
(3)TTS (Text to Speech) Service
In order to ensure the security of your account and better provide you with high-quality services, we will collect and use the information generated by your use of Verbalink open platform TTS services. Based on different devices, systems and versions, as well as the permissions determined by developers when integrating and using our products and/or services.
Types | Details of personal information | Processing purposes |
---|---|---|
Text | Text | Provide online text to speech service after text input |
Log information | Your detailed usage of the Verbalink Open Platform, including your product service usage record, search and query content, visited page address, browser type, network status, operator, language used, access date and time, system Records of activities and web pages you visit. We will also collect logs from your device to our API. | Improve and optimize product experience, and ensure service stability and network security through data statistics. Also it helps us to solve the issues that end users encounter when using the Online ASR API. |
Voice | Audio | The text message that is returned after synthesis. |
Equipment information | Device ID (IMEI number), device code (IMSI code), IP address, Android ID (Android unique device ID to provide competency authorization services), OAID (Android devices only), IDFA (iOS devices only), OpenUDID (iOS devices only), and application | As a means of authorized billing and user identification; At the same time, this information will also be used to more accurately locate and solve the problems encountered by developers and end users when using our products and/or services, and avoid conflicts with other applications, so as to provide you with better products and services. |
(4)Machine Translation Service
In order to ensure the security of your account and better provide you with high-quality services, we will collect and use the information generated by your use of Verbalink open platform machine translation services. Based on different devices, systems and versions, as well as the permissions determined by developers when integrating and using our products and/or services.
Types | Details of personal information | Processing purposes |
---|---|---|
Text | Text | Provide machine translation service after text input. |
Log information | Your detailed usage of the Verbalink Open Platform,, including your product service usage record, search and query content, visited page address, browser type, network status, operator, language used, access date and time, system Records of activities and web pages you visit. We will also collect logs from your device to our API. | Improve and optimize product experience, and ensure service stability and network security through data statistics. Also it helps us to solve the issues that end users encounter when using the machine translation API. |
Text | Text | The text message that is returned after translation. |
Equipment information | Device ID (IMEI number), device code (IMSI code), IP address, Android ID (Android unique device ID to provide competency authorization services), OAID (Android devices only), IDFA (iOS devices only), OpenUDID (iOS devices only), and application | As a means of authorized billing and user identification; At the same time, this information will also be used to more accurately locate and solve the problems encountered by developers and end users when using our products and/or services, and avoid conflicts with other applications, so as to provide you with better products and services. |
(5)OCR (Optical Character Recognition) Service
In order to ensure the security of your account and better provide you with high-quality services, we will collect and use the information generated by your use of Verbalink open platform OCR service. Based on different devices, systems and versions, as well as the permissions determined by developers when integrating and using our products and/or services.
Types | Details of personal information | Processing purposes |
---|---|---|
Image | Image | Provide OCR service after image input |
Log information | Your detailed usage of the Verbalink Open Platform,, including your product service usage record, search and query content, visited page address, browser type, network status, operator, language used, access date and time, system Records of activities and web pages you visit. We will also collect logs from your device to our API | Improve and optimize product experience, and ensure service stability and network security through data statistics. Also it helps us to solve the issues that end users encounter when using the ocr API. |
Text | Text | The text message that is returned after recognition |
Equipment information | Device ID (IMEI number), device code (IMSI code), IP address, Android ID (Android unique device ID to provide competency authorization services), OAID (Android devices only), IDFA (iOS devices only), OpenUDID (iOS devices only), and application | As a means of authorized billing and user identification; At the same time, this information will also be used to more accurately locate and solve the problems encountered by developers and end users when using our products and/or services, and avoid conflicts with other applications, so as to provide you with better products and services. |
II.3. Operation log information
Purpose: | Improve and optimize product experience, and ensure service stability and network security through data statistics |
---|---|
Legal basis: | The consent of the data subject (see: Article 6(1) point of the GDPR |
Data retention period: | The data subject may withdraw his or her consent to the data processing at any time, when the consent is withdrawn, the data will be deleted; otherwise the data controller will store and process his or her data until the troubleshoot and maintain system issue is dealt with. |
Processed personal data: | Your detailed usage of the Verbalink Open Platform, including your product service usage record, search and query content, visited page address, browser type, network status, operator, language used, access date and time, system records of activities and web pages you visit. (see: table II. 2.①-⑤ for details of operation log information processed in various services) |
II.4. Equipment information and logs from service calls
Purpose: | Authorization billing purpose and Statistical analysis of the number of calls |
---|---|
Legal basis: | The consent of the data subject (see: Article 6(1) point of the GDPR |
Data retention period: | The data subject may withdraw his or her consent to the data processing at any time, when the consent is withdrawn, the data will be deleted; otherwise the data controller will store and process his or her data until the troubleshoot and maintain system issue is dealt with. |
Processed personal data: | Equipment information and logs from your device to our API (See: table II. 2.①-⑤ for details of Equipment information and logs from service calls processed in various services). |
II.5.Information you submitted to VerbaLink by other means
Purpose: | Provide you with more accurate and personalized product services |
---|---|
Legal basis: | The consent of the data subject (see: Article 6(1) point of the GDPR |
Data retention period: | The Data Controller will store and process the data subjects’ personal data until the existence of the registration. |
Processed personal data: | When you enter the account personal information page of the iFLYTEK Open Platform, you can voluntarily fill in the name, country and region, project name/ industry/ company size/ company name information. |
II.6. Data provided by giving consent to the use of cookies
Our detailed information on the use of cookies is available at the following link:Cookie Policy
II.7. Pushing and displaying customized content for you
Based on the information collected, we can recommend the content that may be of interest to you, including but not limited to recommending to or showing you the latest artificial intelligence products or third-party promotional information, sending marketing materials we think may be of interest to you, or sharing information with the iFLYTEK Open Platform’s associated companies with your consent, so that they can send you information about their products or services and marketing materials they think may be of interest to you.
III. How we entrust to process, share, transfer, and publicly disclose your personal data
III.1. Entrusted processing of data
We will implement confidentiality clauses into our agreements with our employees whom we entrust to process personal data, and require them to process personal data in accordance with our requirements, this Privacy Policy and any other related confidentiality and security measures.
III.2. Disclosure of data
We will only publicly disclose your personal data in the following circumstances:
- Your explicit consent is obtained;
- Disclosure based on law: We may publicly disclose your personal data in accordance with laws, legal procedures, litigation or mandatory requirements of government authorities.
III.3. Information on data transfers
The data controller will usually not transfer your personal data to third countries (i.e. countries that do not qualify as EU Member States), but the data controller may transfer your personal data to third countries when based on the relevant processing purposes in part 4 (as indicated in the table below). The data controller may transfer your personal data to parties that cooperate with it under contract, exclusively for the purpose of performing a contract concluded with you or with your company. Your personal data may also be transferred on an ad hoc basis (if absolutely necessary, for example in connection with a legal dispute or for the determination of the correct financial or accounting treatment of a transaction) to service providers engaged by the data controller, such as lawyers, auditors or financial advisors, who are subject to professional or contractual confidentiality obligations.
Recipients / categories of recipients:
Recipients | Legal basis for data transfer | Purpose of data transfer |
---|---|---|
Data Processor: Server supplier at Frankfort, Germany | Legitimate interest of the data controller | Data processor, provide the server as a data processing carrier for the data controller and processor to use |
Data Processor: Cantab Research Limited (trading as "Speechmatics") at Ireland, United States Of America | Consent of the data subject | Data processor, provide short form ASR (Automated Speech Recognition) service, long form ASR service in some languages Privacy Policy |
IV. How we store and protect your personal data
The personal data collected about you will be stored on a designated server in Frankfurt, Germany. We completely adhere to the provisions of the GDPR. Generally, we only retain your personal data for the shortest time necessary to achieve the corresponding purpose.
IV.1. Data Security Measures
- We will adopt security protection measures that comply with industry standards, including establishing reasonable system specifications and security technologies to prevent your personal data from unauthorized access, use and modification to avoid data damage or loss. For example, our network services are protected with encryption technologies such as transport layer security protocols, providing browsing services through https and other methods, to ensure the security of user data during transmission; we adopt encryption technologies (TLS, SSL) , anonymization and protection mechanisms to encrypt and store user personal data and isolate it through isolation technology; we manage and regulate the storage and use of personal data by establishing a data classification and grading system, data security management specifications, and data security development specifications; we only allow our employees to access personal data through confidentiality agreements with use data contacts and other methods, and set up strict access rights control and monitoring mechanisms to this end, and require all personnel who come to contact with your personal data to fulfill the corresponding confidentiality obligations. Failing to fulfill these obligations, they will be held legally responsible or their legal relationship with Verbalink will be suspended; we will hold security and privacy protection training courses to strengthen employees' awareness of the importance of protecting personal data.
- We will take all reasonable and feasible measures to ensure that irrelevant personal data is not collected. We will only retain your personal data for the period required to achieve the purpose stated in this Privacy Policy, unless the retention period needs to be extended or permitted by law.
- The Internet is not an absolutely secure environment, and email, instant messaging, and communication with other users are not encrypted. We strongly recommend that you do not send personal data through such methods. Please use a complex password to help us keep your account secure.
- We will make every effort to ensure and guarantee the security of any information you send to us. If the physical, technical or management protection facilities are damaged, the information is illegally authorized to be accessed, publicly disclosed, tampered with, or destroyed, and your legal rights and interests are damaged as the result, we will bear the corresponding legal responsibility.
- Once any personal data security incident occurs unfortunately, we will promptly inform you of the following in accordance with the GDPR: the basic situation and impact of the security incident, the disposal measures taken or to be taken by us, suggestions for your active prevention and for reducing risks, and remedial measures for you, etc. We will promptly inform you of the relevant circumstances of the incident by email, push notification, etc. Besides, we will also actively report the occurrence of the data breach incident and the handling process of such incidents in accordance with the requirements of the GDPR.
V. Your Rights
In accordance with the provisions of the GDPR, we guarantee that you exercise the following rights to your personal data. You can refer to the following steps for related operations:
V.1. Right of access
Visitors may request information from the Data Controller on the circumstances of the processing of their personal data and may obtain access to such personal data.
You can access basic information such as email address, login password, etc. through the following steps:
- Enter the Website and log into your account of the platform;
- Click the account name you have logged in and click the basic information menu;
- Click on basic information or security settings;
- View the information you need. The Website is related to website business, and the specific operations may vary slightly with the iteration of the version. If failing to access these personal information through the above operations and pages, you can contact us at any time through the Website-[Technical Support]-[Submit Request].
V.2. Right to rectification
Visitors may request the Data Controller to correct or complete inaccurately recorded personal data.
You can change the basic information such as email-address, etc. through the following steps:
- Enter the Website and log into your account;
- Click the account name you have logged in and click the basic information menu;
- Click the basic information or security settings;
Change the information as needed. Different versions of Website may have slight difference in operations. If you are unable to correct this personal information through the above operations and pages, you can contact us at any time through the Website-[Homepage]-[Security setting]-[Modify].
V.3. Right to erasure
Visitors may request to erase their personal data processed by the Data Controller. We will always inform you if your personal data cannot be erased for any reason.
If you want to delete your account, please send an email to service@danutecheu.com or submit request. We will process your request as soon as possible, which may take about three working days. Please note that you cannot log in with your account after account deletion and your account cannot be restored. After the offline verification is done and the corresponding risks are notified to you, we will delete your personal data as requested by you. You can submit a request to us to delete your personal data in the following cases:
- The personal data is no longer necessary in relation to the purposes for which they were collected or otherwise processed
- You withdraw your consent on which the processing is based on, and there is no other legal ground for the data processing.
- Your personal data have to be erased for compliance with a legal obligation
- You object the data processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or you object the processing pursuant to Article 21(2) of the GDPR
- Your personal data have been unlawfully processed
- Where your personal data have been collected in relation to the offer of services to a person under the age of 16.
V.4. Right to restriction of processing
Visitors may request the restriction of processing if they contest the accuracy of their personal data, or if they have a need for personal data that would otherwise be deleted (for example, to pursue their own legal claims) or if they have objected to the processing of their data as set out below.
V.5. Right to data portability
Visitors may request the Data Controller to electronically transfer the personal data processed by the Data Controller to you as the Data Subject or to another data controller. The Data Controller will always inform visitors if their data may not be transferred for any reason.
V.6. Right to object
Visitors may object to the processing of their data, for example if the Data Controller would use such data to send them advertising, contract offers or similar commercial communications.
V.7. Right to lodge a complaint
Visitors have the right to lodge a complaint with Hungary’s National Authority for Data Protection and Freedom of Information if they believe that the Data Controller has violated any legislation on the processing of personal data (address: 1055 Budapest, Falk Miksa utca 9-11., phone: +36-1-391-1400, e-mail: ugyfelszolgalat@naih.hu, website: www.naih.hu).
V.8. Right to file a lawsuit
Visitors have the right to file a lawsuit with the court that has jurisdiction over their domicile or residence (at their choice) if they believe that the Data Controller has violated their rights in the course of the processing.
VI. How we handle minors' personal information
We attribute great importance to the protection of children's personal data. The Website protects children's personal data in accordance with the GDPR. We treat anyone under 16 years old as a child. Our products or services are mainly for adults, and children cannot create their own user accounts without the consent of parents or legal guardians. In the case of collecting personal data of children with the consent of parents or legal guardians, the Website will only use or publicly disclose this information when allowed by law, after parents or legal guardians expressly agree, or necessary to protect children. If we find that we have collected children ’s personal information without prior verifiable consent by the parent or the legal guardian, we will delete the relevant data as soon as possible.
VII. How this Privacy Policy is updated
The Privacy Policy of the Website may change from time to time, in order to provide the visitors with up to date information regarding the data processing activity.
- The Website will not reduce your rights under this Privacy Policy without your explicit consent. The Data Controller will post any changes to the Privacy Policy on a dedicated page. At the same time, the Website will archive the old version of this Privacy Policy for your reference.
- For major changes, the Data Controller will also provide more prominent notifications, e.g. notifying you through pop-up notification on the Website.
• The services of the Website and the data processing activity has undergone major changes, such as the purpose of processing personal data, the type of personal data processed, and the use mode of personal information, etc.;
• The Data Controler has undergone major changes in control and other aspects, such as owner changes caused by mergers and acquisitions, etc.;
• The main objects of personal data sharing, transfer or public disclosure have changed;
• There are major changes in your rights to participate in the processing of personal data and how you exercise them;
• When there is a high risk as indicated by the personal data security impact assessment report;
• With the implementation of policies or laws, changes are made in response to national policies or laws and regulations.
VIII. Contact us
If you have any questions or suggestions about this Privacy Policy in the process of using the Website, please contact us based on the following contact information: E-mail: chenyue@verbalinkeu.com, mail.verbalinkeu.com. In order to ensure that we can efficiently handle your problems and give you feedback timely, you need to submit your identification certification, effective contact information, written requests and related evidences. We will process your request after verifying your identity. In general, we will make a reply within 72 hours.