Important Notice
Note on language: This English version is a concise summary provided for convenience only. The Chinese version (privacy_zh.md) is the authoritative, legally binding text. In case of any inconsistency between the two versions, the Chinese version shall prevail.
1. Introduction and Key Points
Chengdu Hanxi Technology Co., Ltd. ("we," "us," or "Hanxi") operates GrowingX (organization app), GrowingX Go (trainee app), and jcppc.net (collectively, the "Services"). We process personal information in accordance with the PRC Personal Information Protection Law, Cybersecurity Law, Data Security Law, and other applicable regulations.
Key points:
- We are a software platform, not a training institution. GrowingX / GrowingX Go is a SaaS management tool for education and training organizations. Hanxi is not a training institution and does not conduct education/training business itself. Disputes relating to training services, fees, refunds, or teaching quality should be directed to the organization you enrolled with; Hanxi does not assume liability for such disputes. See § 8 below and Section 17 of the Terms of Service.
- Two distinct data-processing relationships: (a) account registration information (phone number, email, password) that you provide directly to us is processed by Hanxi as the personal information processor (controller); (b) organization-controlled data — trainee, customer, staff, scheduling, training, order, and financial records that an organization enters and manages in GrowingX — is controlled by that organization, with Hanxi acting only as an entrusted processor under the Data Processing Agreement ("DPA") at https://jcppc.net/dpa. See § 7.
- Sensitive personal information (e.g., precise location data, images/video containing biometric-like facial data) is separately disclosed and requires separate consent. See § 1.4 below.
- Minors: GrowingX Go may be used by trainees who are minors. Processing of children's (under 14) personal information is governed by the Children's Privacy Policy.
- Your rights: you may access, copy, correct, delete your information, withdraw consent, or delete your account. We respond within 15 business days. See § 6.
This Policy should be read together with the Terms of Service, the Data Processing Agreement (DPA), the Children's Privacy Policy, and the Platform Rules.
2. Information We Collect
2.1 Information You Provide
- Account data: phone number, email, password (encrypted), display name, avatar.
- Organization data (GrowingX): legal business name, unified social credit code, business license, campus addresses, contact persons, verification documents.
- Staff data: name, role, campus assignment, contact details.
- Trainee/customer data (organization-controlled): name, gender, date of birth, contact details, guardian information, training records, orders, and session consumption data.
- Content: training videos, check-in photos, avatars, organization logos, course materials uploaded by you or the organization.
- Customer support records: communications and supporting materials you provide when contacting support.
2.2 Information Collected Automatically
We collect device information (model, OS version, device identifiers, network type), log data (IP address, access times, operation logs, crash reports), usage data, and security/anti-fraud signals (device fingerprint, abnormal login patterns) necessary for operating the Services securely.
With your separate authorization, we may also collect precise location data (GPS) for training check-in verification, and access your camera/photo library/microphone/storage/push-notification permissions for the corresponding features (uploading videos or photos, receiving notifications, etc.). You may withdraw any such permission via your device settings at any time; doing so may disable the related feature.
2.3 Information from Third Parties
With lawful authorization, we may receive trainee-related information from organization users, or transaction/verification data from payment, SMS, and app-distribution partners.
2.4 Sensitive Personal Information
We may process the following categories of sensitive personal information: (a) precise location data used for GPS check-in verification; (b) facial imagery contained in check-in photos or training videos; (c) personal information of children under 14, which is treated as sensitive by law; (d) identity-document information used for organization verification or invoicing; (e) guardian identity/relationship information. We will separately notify you of the necessity of processing such information and its impact on your rights, and obtain your separate consent (or verifiable guardian consent for minors) before processing. You may decline, but related features may become unavailable.
3. How We Use Information
We use personal information to: (1) provide, operate, and improve the Services; (2) register and authenticate accounts and manage permissions; (3) support scheduling, check-in, training records, orders, session consumption, and financial statistics; (4) send service notices, verification codes, and necessary alerts (not unsolicited marketing messages); (5) safeguard security, detect fraud, and resolve disputes; (6) comply with legal and regulatory obligations; and (7) other purposes for which you have given separate consent (e.g., product research, or AI model improvement using de-identified or anonymized data). We do not use personal information for purposes unrelated to and not disclosed in this Policy without obtaining renewed consent.
4. Cookies and Similar Technologies
We and our service providers may use cookies, local storage, and similar technologies on jcppc.net and within the apps to maintain login sessions, remember preferences, measure usage, and protect account security. Essential cookies required for core functions (e.g., login) cannot be disabled; you may manage non-essential cookies through your browser or device settings, which may affect certain features.
5. Sharing, Transfer, and Disclosure
5.1 Sharing
We do not share personal information with unrelated third parties. We may share information only: (a) with your explicit consent; (b) with vetted service providers under contractual data-processing limits (cloud storage, SMS, payment, push notification, and mapping/location providers — see table below); (c) within an organization's own permission structure (staff, campuses); or (d) as required by law or requested by competent authorities.
| Partner Type | Purpose | Data Shared |
|---|---|---|
| Cloud storage providers | Object storage & content delivery | Uploaded files, photos, training videos |
| SMS providers | Verification codes & notifications | Phone number, code content |
| Payment institutions | Subscription/service fee processing | Order number, amount, payment status |
| Push notification providers | In-app notifications | Device push token, notification content |
| Map/location providers | Check-in location verification | Authorized location coordinates |
We require these partners to meet data-protection standards no lower than this Policy and to process data only for the stated purposes. A detailed list of integrated third-party services is available upon request at coach_lv@jcppc.net.
5.2 Transfer and Public Disclosure
We do not transfer personal information to other parties except with your consent, or in connection with a merger, acquisition, or bankruptcy where the successor must continue to honor this Policy. We disclose personal information publicly only with your consent or as required by law, legal process, or government authorities.
6. Entrusted Processing of Organization-Controlled Data
For data that an organization enters, imports, generates, or manages in GrowingX (trainee/customer records, staff data, scheduling, training, orders, and financial data), the organization is the personal information processor (controller), and Hanxi acts only as an entrusted processor, processing such data solely as necessary to provide the SaaS Service and per the organization's instructions, under the DPA. Organizations are responsible for obtaining lawful consent (including verifiable guardian consent for minors), responding to data-subject requests, and managing internal access controls. Hanxi is not the responsible party for the accuracy or lawfulness of data entered by an organization, nor for training-business disputes. If your information is organization-controlled, please contact that organization directly to exercise your rights; we will assist by forwarding verified requests where appropriate.
7. Storage Location and Retention
Personal information collected within mainland China is stored on servers located in mainland China. Any cross-border transfer will follow applicable legal requirements (security assessment, standard contract, or certification) and require your separate consent unless otherwise provided by law.
We retain personal information only for as long as necessary for the purposes described in this Policy, applying different retention periods by category (e.g., account data for the life of the account plus a reasonable period after deletion; transaction records per the minimum periods required by tax/finance regulations; logs and security data per minimum cybersecurity retention requirements; media content per the organization's business retention cycle). After the applicable period, or upon account deletion, we delete or anonymize the information unless longer retention is required by law.
8. Security Measures; Platform Is Not a Training Institution
We use encryption in transit (HTTPS/TLS), access controls, tenant/campus data isolation, the principle of least privilege, operational auditing, and incident-response procedures to protect your information. No method of transmission over the Internet is completely secure. If a personal information security incident occurs, we will notify affected users and report to regulators as required by law.
Reminder: GrowingX / GrowingX Go is a software tool. Hanxi does not operate any training business, is not a party to the training contract between an organization and its trainees, and does not handle training fee collection or refunds. Disputes concerning training services should be resolved directly with the relevant organization, through consumer-protection channels, arbitration (if agreed), or the courts.
9. Your Rights
Subject to applicable law, you may: (1) access and copy your personal information; (2) correct or supplement inaccurate information; (3) request deletion where legally permitted; (4) withdraw consent (without affecting the validity of processing carried out before withdrawal); (5) delete your account via in-app settings or by contacting us; (6) request a copy of your data or, where technically feasible, its transfer; and (7) object to or request an explanation of automated decision-making.
Contact coach_lv@jcppc.net to exercise these rights. We will verify your identity and respond within 15 business days (or a reasonable extended period for complex requests, which we will communicate to you). If your information is organization-controlled, you may also contact that organization directly.
10. Children's Privacy
GrowingX Go may be used by trainees who are minors. Users under 14 must have a guardian read and accept the Children's Privacy Policy and provide consent on the child's behalf. Users aged 14–18 should review this Policy with guardian guidance and obtain guardian consent. Organizations must obtain verifiable guardian consent before entering a minor's data. We do not knowingly provide services beyond what is necessary to children under 14 without guardian involvement, and we do not use children's data for profiling or personalized advertising.
11. Automated Decision-Making and AI
Features such as smart segmentation, business forecasting, and content recommendations are automated analytical tools whose outputs are for reference only and do not constitute a final decision affecting any individual. We do not make decisions that have a significant impact on your rights based solely on automated decision-making. Where we use de-identified or anonymized data to improve AI features, and where identifiable personal information is used for model training, we obtain separate consent or another lawful basis and offer an opt-out. AI-generated synthetic content is labeled as required by law.
12. Scope of This Policy
This Policy applies to personal-information processing activities within GrowingX, GrowingX Go, and jcppc.net. It does not apply to third-party websites or services linked from our Services (e.g., payment gateway pages, map navigation), which are governed by those third parties' own privacy policies, nor to offline records kept by an organization outside of the Services.
13. Updates to This Policy
We may update this Policy from time to time. Material changes (e.g., to processing purposes, methods, categories of information collected, or sharing/disclosure practices) will be announced via in-app notice, website announcement, or email before taking effect. Continued use of the Services after the effective date of an update constitutes acceptance of the updated Policy; if you disagree, you should stop using the Services and may request account deletion. The latest version is always published at https://jcppc.net/privacy-en (Chinese version: https://jcppc.net/privacy).
14. Contact Us and Complaint Channels
Operator: Chengdu Hanxi Technology Co., Ltd.
Email: coach_lv@jcppc.net
Website: https://jcppc.net
Registered address: Chengdu, Sichuan Province, People's Republic of China (as stated on our business license)
For questions, comments, or complaints about this Policy, please contact us using the details above; we will respond within a reasonable time after verifying your request.
Reminder: Hanxi provides a software platform and is not a training institution. Disputes between you and an organization over training services, fees, refunds, or teaching quality should first be addressed with that organization, or resolved via consumer-protection associations, competent regulators, agreed arbitration, or courts of competent jurisdiction. Hanxi does not mediate or advance payment for such disputes.
You may also file a complaint regarding personal-information protection with the PRC cyberspace administration (12377, https://www.12377.cn), the telecommunications regulator (12321, https://www.12321.cn), public security network-security authorities (https://www.cyberpolice.cn), or market-regulation authorities (12315, https://www.12315.cn).
(End)