Introduction
This English version is a concise summary for reference only. It is not a full translation. The Chinese version, "GrowingX / GrowingX Go 儿童个人信息保护规则" (available at https://jcppc.net/children-privacy), is the legally binding and authoritative text. In the event of any inconsistency or conflict between this English version and the Chinese version, the Chinese version shall prevail and shall be used for all legal, regulatory, and dispute-resolution purposes.
Chengdu Hanxi Technology Co., Ltd. ("we," "us," or "Hanxi") has adopted these Children's Personal Information Protection Rules ("these Rules") pursuant to Article 31 of the PRC Personal Information Protection Law, which requires personal information handlers to obtain parental or guardian consent and adopt special processing rules before processing the personal information of minors under the age of 14.
These Rules form a special, priority-applicable supplement to our Privacy Policy for matters concerning Children's personal information, and apply to GrowingX (the organization-facing app), GrowingX Go (the trainee-facing app), and related services provided via jcppc.net. For matters not addressed in these Rules, our Privacy Policy, Terms of Service, and Platform Rules apply.
Parents or other legal guardians ("Guardians") should read these Rules carefully before allowing an organization to create a trainee record for a Child or before using the Services on a Child's behalf.
Important note on our business model: GrowingX is a B2B SaaS software tool for training organizations. In most scenarios, trainee data is entered into the system by the training organization, not by the Child or Guardian directly. Accordingly, the organization is primarily responsible for obtaining Guardian consent and providing the required notices; we act as an entrusted processor with respect to organization-controlled data. See Section 8 below.
1. Definitions
- "Child" / "Children": a minor under the age of 14 (not including 14), consistent with Article 31 of the Personal Information Protection Law.
- Minors aged 14 to under 18 ("Teen Users") are not covered by these Rules; they are governed by our Privacy Policy and Terms of Service, and should use the Services under Guardian guidance and with Guardian consent.
- "Guardian": a Child's parent or other person with lawful guardianship.
- "Organization User": a training organization and its authorized staff/administrators using GrowingX.
- "Organization-Controlled Data": business data entered, imported, generated, or managed by an Organization User in GrowingX, as defined in our Data Processing Agreement ("DPA").
- "Delete": to render personal information unretrievable and inaccessible within systems under our actual control.
- "Anonymize" (匿名化): to process personal information such that a specific individual can no longer be identified and the process cannot be reversed, after which the information is no longer personal information.
- "De-identify" (去标识化): to process personal information such that a specific individual cannot be identified without additional information, while re-identification remains possible if combined with additional information.
2. Age Tiers
| Age | Applicable Rules | Who Consents |
|---|---|---|
| Under 14 (Child) | These Rules | Guardian, on the Child's behalf |
| 14 to under 18 (Teen User) | Privacy Policy / Terms of Service | The Teen User, under Guardian guidance |
| 18 and above | Privacy Policy / Terms of Service | The user, on their own behalf |
We and Organization Users identify age primarily from the date of birth recorded during trainee enrollment or Guardian binding. Where age cannot be reliably confirmed, or there is reasonable cause to believe a user may be a Child, we apply the higher protection standard for Children until the status is reasonably confirmed.
3. Collection — Minimum Necessary Scenarios
We follow the minimum necessary principle. Representative scenarios in which Children's personal information may be processed:
| Scenario | Data Collected | Sensitive? | Purpose |
|---|---|---|---|
| Trainee enrollment / profile | Name, gender, date of birth, photo, campus/class | Yes (photo) | Identification, scheduling, training management |
| Guardian binding | Guardian name, phone number, guardianship relationship | No | Establish Guardian–Child link for rights exercise |
| Training check-in | GPS location (with authorization), time, device info | Yes (location) | Attendance verification, records |
| Training video | Video containing the Child's image, timestamp, location | Yes (may include biometric-related content) | Training archive, coaching feedback, dispute evidence |
| Events / leaderboard | Name/nickname, avatar, scores, ranking | No (generally no full ID data shown) | Event display and ranking |
| Orders / session consumption | Guardian contact info, package and consumption records | No | Enrollment and billing management |
| Customer support | Communication content, supporting materials | Depends | Handling inquiries, complaints, disputes |
| Security / risk control | Device info, logs, anomaly flags | No (not primarily for identifying a specific Child) | Account and system security, anti-fraud |
| Statistics / dashboards | De-identified or anonymized aggregate data | No | Organization analytics, product improvement |
We do not proactively require Organization Users or Guardians to provide a Child's national ID number, household registration, medical history, or other highly sensitive information unrelated to training services, unless required by law or separately consented to.
4. Guardian Consent — Verifiable Methods
Consent to process a Child's personal information must be obtained from a Guardian; a Child's own action is never treated as valid consent (see Section 9). Before entering a Child's information, Organization Users must obtain verifiable Guardian consent through one or more of the following methods, and retain consent records:
| Method | How it works | Record kept by |
|---|---|---|
| Offline written consent form | Organization and Guardian sign a paper or e-signed "Trainee Data Collection and Use Consent Form" | Organization User |
| In-platform e-consent template | Organization generates a consent template in GrowingX; Guardian e-signs / confirms | Platform (signature record) + Organization (signed copy) |
| GrowingX Go Guardian binding | Guardian registers via phone-number verification code and binds to the Child's trainee profile, confirming they have read these Rules | Platform (binding/confirmation logs) |
| SMS / voice re-verification | For disputed or high-risk cases, secondary verification of Guardian identity and consent via SMS code or phone call | Platform (verification logs, retained ≥ 2 years or until dispute resolution) |
We recommend combining the offline written form with the in-platform e-consent template to build a traceable, evidentiary consent chain. Guardians may request access to their consent records at any time (Section 7).
Consent must clearly and specifically cover the purpose, data types, processing methods, and sharing scope. Where the purpose, method, or categories of data materially change, renewed Guardian consent is required. Guardians may withdraw consent at any time; withdrawal does not affect the validity of processing already carried out, but we and the Organization User will stop further processing and delete or anonymize the data per Section 6, unless retention is legally required.
5. Use — No Marketing to Children
Within the scope of Guardian consent, Children's personal information is used only to: (1) provide core training services (enrollment, scheduling, check-in, records, timetables, events); (2) safeguard account and training security; (3) handle inquiries, complaints, and disputes; (4) comply with legal obligations; and (5) other purposes separately consented to by the Guardian.
We do not, and do not permit Organization Users to, use Children's personal information for advertising directed at Children, marketing messages to Children, or any commercial marketing unrelated to core training services. We do not build user profiles of Children or make automated decisions with significant effects on Children based solely on their personal information.
6. Sharing, Transfer, and Disclosure; Domestic Storage; Deletion / Anonymization
In most scenarios, the Organization User is the personal information handler (data controller) for Children's data entered into GrowingX ("Organization-Controlled Data"), and we act as an entrusted processor, processing such data only as necessary to provide the SaaS service and per the Organization's instructions. The rights and obligations between us and the Organization User for such data are governed by our Data Processing Agreement (DPA). Account registration information provided directly to us by trainees/Guardians via GrowingX Go is processed by us as a handler under our Privacy Policy.
We do not share, transfer, or disclose Children's personal information with third parties without explicit Guardian consent, except: (a) with vetted service providers (cloud storage, SMS, push notification, maps/location) under contracts requiring protection no lower than these Rules; (b) display to authorized staff within an Organization's own permission scope; (c) as required by law or a competent authority; or (d) in a merger, acquisition, or bankruptcy liquidation, where the successor must continue to honor these Rules or obtain fresh consent.
Domestic storage: Children's personal information is stored within mainland China. We do not transfer it overseas except as required by law, or where a cross-border transfer is genuinely necessary and we have completed the required security assessment/standard contract procedures and obtained separate Guardian consent.
Deletion / anonymization: Upon account cancellation, Guardian withdrawal of consent, a trainee's departure and archival period expiry, or a valid deletion request, we delete the Child's personal information (making it unretrievable and inaccessible) or anonymize it (irreversibly de-identified) as appropriate, except where a longer retention period is required by law or is reasonably necessary for an ongoing dispute, security investigation, or regulatory matter — in which case use is restricted to that specific purpose only.
7. Sensitive Scenarios: Training Video and GPS Check-In
Training video: may contain a Child's image and is treated as sensitive personal information. It is used only for training archiving, coaching feedback, and necessary dispute evidence. Any use for external promotion or social media publication requires separate, explicit Guardian consent and can be taken down on Guardian request. Videos are stored domestically with role-based access control, audit logging, and a retention period set by the Organization within reasonable limits; they are deleted or anonymized under Section 6 upon trigger events. We do not use training video content to build facial-recognition databases or behavioral profiles unrelated to training services.
GPS check-in / location data: used only to verify attendance location at the moment of check-in — not for continuous background tracking, movement-pattern analysis, or location-based marketing. Location access can be disabled in device settings (which may disable check-in features or require an alternative verification method). Location data is stored with the corresponding attendance record and deleted or anonymized under the same rules as training records.
Device and security/risk-control information (device model, device identifiers, anomaly flags) is not primarily used to identify a specific Child and is used solely for account/system security and anti-fraud purposes.
8. Organization User Responsibilities (Controller Obligations)
Training organizations that enter and manage Children's personal information in GrowingX are generally the personal information handler (data controller) under the PIPL and must independently comply with all applicable legal obligations. We act as an entrusted processor under the Data Processing Agreement (DPA) and do not become the controller, or the responsible party for the organization's training business, merely by providing SaaS technical support.
Organization Users must: (1) obtain verifiable Guardian consent before entering a Child's information, using the methods in Section 4, and retain consent records; (2) collect only the minimum information necessary; (3) manage staff access on a least-privilege basis and revoke access promptly upon staff departure; (4) provide the required notices to Guardians; (5) promptly notify us and affected Guardians of any security incident and cooperate on remediation and regulatory reporting; (6) never use Children's personal information for unrelated commercial marketing, sale, or unlawful provision to third parties; (7) take the lead in responding to Guardian rights requests (Section 9), with our technical assistance as entrusted processor; and (8) comply with the special rules in Section 7 for training video and location data.
Our platform features (enrollment forms, Guardian-binding components, e-consent templates) are provided to assist Organization Users in meeting these obligations but do not shift the controller's legal responsibilities to us, nor do they constitute our guarantee that valid consent has actually been obtained. Legal liability for an Organization User's violation of this Section rests with the Organization User; we may suspend or restrict the relevant organization account after verification, and will cooperate with regulatory investigations.
9. Guardian Rights
Guardians have the right to: (1) access and obtain copies of a Child's personal information; (2) correct or supplement inaccurate or incomplete information; (3) request deletion where legally permitted; (4) withdraw consent at any time; (5) cancel the Child's GrowingX Go account; (6) refuse processing unrelated to core training services; (7) request access to consent and processing records; (8) request an explanation of our processing rules; and (9) file complaints (Section 11).
Children must not consent on their own behalf, and we do not knowingly solicit consent directly from Children or design features that let Children bypass Guardian supervision to self-register or self-consent. If we discover a Child has been registered, or information collected, without valid Guardian consent, we will promptly stop the relevant processing and delete the data collected (unless retention is legally required).
How to exercise these rights: via the Guardian-binding and account settings features in GrowingX Go; by contacting the Child's training organization (which, as controller, will take the lead in responding); or by emailing coach_lv@jcppc.net with the Child's name, registered phone number (or trainee ID), organization name, and the specific request.
We will respond within 15 business days, or the period required by law. To protect the Child, we may require proof of identity or guardianship before processing a request. Where a request concerns Organization-Controlled Data, we will forward it to the relevant Organization after verification; if the Organization fails to respond within a reasonable time, the Guardian may escalate to us at the email above, and we will follow up and provide further reasonable assistance.
10. Security Measures
We apply security measures equal to or stricter than those described in our Privacy Policy, including: transport encryption (HTTPS/TLS) and storage-side access controls; role-based access control and least-privilege principles, with dedicated access restrictions and audit logging for sensitive content such as training video; operation logging and automated anomaly detection; staff confidentiality training and access agreements; and contractual security requirements for subprocessors no lower than these Rules.
In the event of a security incident affecting Children's personal information (leakage, tampering, loss, or unauthorized access), we will activate our incident response plan, take remedial measures, notify affected Guardians in a reasonable manner as required by law, and report to regulators where applicable. Incidents caused by an Organization User (permission misconfiguration, account sharing, device theft, staff misconduct) are subject to the notification obligations in the DPA, Section 4.
We do not use Children's personal information for profiling or personalized commercial advertising unrelated to core training services.
11. Complaints and Regulatory Channels
Guardians may contact us at coach_lv@jcppc.net with the Child's name, registered phone number, organization name, and relevant facts/evidence, or contact the Child's training organization directly. We will respond within 15 business days.
Guardians may also report to: the National Center for Reporting Illegal and Unhealthy Information (12377); the National Hotline for Protection of Minors' Rights (12428); local cyberspace administration, public security, or market regulation authorities; or file a lawsuit with a court having jurisdiction (courts in Chengdu, per our Terms of Service).
12. Updates to These Rules
We may update these Rules from time to time. Material changes (to purposes, methods, data categories, or sharing scope) will be communicated via in-app notice, website announcement, SMS, or other reasonable means, and renewed Guardian consent will be obtained where required. The current version is available at https://jcppc.net/children-privacy. If a Guardian disagrees with an update, they may decline, stop using the Services on the Child's behalf, and request deletion of the Child's data.
Matters not addressed in these Rules are governed by our Privacy Policy, Terms of Service, Platform Rules, and DPA. As stated above, this English version is for reference only; the Chinese version controls in the event of any discrepancy.
13. Contact Us
Operator: Chengdu Hanxi Technology Co., Ltd.
Email: coach_lv@jcppc.net
Website: https://jcppc.net
Registered address: Chengdu, Sichuan Province, People's Republic of China (as stated on our business license)
For questions, comments, or complaints about children's privacy, please contact us using the details above.
(End)