Important Notice
The Chinese version at https://jcppc.net/dpa prevails. This English text is for reference only.
This Data Processing Agreement (“Agreement”) is entered into between the Organization User that activates and uses GrowingX / GrowingX Go (“Customer” or “you”) and Chengdu Hanxi Technology Co., Ltd. (“Hanxi” or “we”).
By accepting the Terms of Service, signing a commercial contract, or using the GrowingX organization console, you agree to this Agreement. For processing of Organization-Controlled Data, this Agreement prevails over conflicting provisions in the Terms or Privacy Policy.
1. Roles
For Organization-Controlled Data (trainee/customer records, schedules, training records, orders/consumption, staff permissions, and related files uploaded or generated in GrowingX): Customer is the personal-information controller (entrusting party); Hanxi is the entrusted processor and processes such data only as needed to provide the SaaS Service.
Hanxi is not a training provider and does not assume liability for training contracts, tuition, refunds, or teaching quality (see Terms Chapter 17).
2. Customer Obligations
Customer must ensure a lawful basis (including verifiable guardian consent for children under 14), fulfill controller duties under applicable PRC law, manage staff access with least privilege, and not instruct Hanxi to process data unlawfully.
3. Hanxi Obligations
Hanxi will process Organization-Controlled Data only for Service purposes; apply reasonable technical and organizational security measures; limit access to authorized personnel; impose confidentiality on staff and necessary subprocessors; and delete or anonymize data after termination as required by the Terms and Privacy Policy (except legal retention).
4. Data-Subject Rights, Incidents, and Assistance
The parties will assist each other in responding to data-subject requests. Requests about Organization-Controlled Data are generally referred to Customer. Security incidents will be promptly notified between the parties with cooperation on investigation and lawful reporting. Upon written request and within reasonable commercial cost, Hanxi may provide necessary descriptions to support Customer’s regulatory inquiries or assessments (subject to confidentiality and multi-tenant security).
5. Subprocessors and Cross-Border
Hanxi may use infrastructure subprocessors (cloud storage, SMS, push, payments, maps, etc.) under substantially equivalent protections. Organization-Controlled Data is stored in mainland China by default. Cross-border transfer requires Customer’s written instruction/consent and completion of legally required procedures.
6. Term, Liability, and Law
Processing lasts only as long as needed for the Service. Liability caps follow Terms §12.6. Governing law and venue follow the Terms (Chengdu courts). Contact: coach_lv@jcppc.net.
(End)