Skip to content
GrowingXHanxi Technology
Home Ecosystem Access Support Terms Software Rules Data Processing Privacy Children's Privacy Support 中文

LEGAL GrowingX

Privacy Notice — Short Form

隐私说明(简明版)

Last Updated: August 16, 2026 · Effective Date: August 16, 2026

中文 ↗
CONTENTS
  1. 01Important Notice
  2. 021. Who We Are and What Roles We Perform
  3. 032. What We Process and Why
  4. 043. Minors and Children
  5. 054. Permissions, SDKs, and Suppliers
  6. 065. Artificial Intelligence and Automated Processing
  7. 076. Your Rights
  8. 087. Full Texts and Contact Channels

Important Notice

Document Version: 2026.08.16.1

Last Updated: August 16, 2026

Effective Date: August 16, 2026

Current status: Engineering compliance draft pending external counsel's written sign-off on this exact version and SHA-256. This document is not lawyer-approved.

This Notice only helps you understand the key points. It does not replace, reduce, or alter the full Privacy Policy. If this Notice is inconsistent with the full Policy, the full Chinese Policy and mandatory law prevail.

1. Who We Are and What Roles We Perform

Chengdu Hanxi Technology Co., Ltd. provides the GrowingX / GrowingX-G SaaS tools and is not a training organization.

  • Hanxi is the personal information handler for account registration, authentication, platform security operations, customer support, and other activities for which we independently determine the purposes and means.
  • For trainee, Guardian, staff, customer, scheduling, training, order, and financial data entered, imported, generated, and managed by an Organization, the Organization determines the purposes and means; Hanxi processes the data only as an entrusted processor under the Organization's lawful instructions and the DPA.

2. What We Process and Why

We process only information necessary for account authentication, permissions, enabled functions, support, security, and legal obligations. The full Policy and just-in-time notices describe the specific categories, purposes, legal bases, and retention periods. Non-essential marketing, analytics, sensitive permissions, or new purposes may not be bundled with the core Service.

3. Minors and Children

Users under 18 may not self-register; an Organization must invite them and a Guardian must complete verification and authorization. All personal information of a Child under 14—including phone numbers, device information, logs, order/session-consumption data, and push identifiers—is sensitive personal information and is governed by the Children's Personal Information Protection Policy.

An SMS one-time password proves only that the applicant controls the relevant phone number; it does not by itself prove a guardianship relationship. Guardian authorization must also include a guardianship declaration and matching against the Organization's existing records, with enhanced verification for disputed, anomalous, or high-risk cases.

4. Permissions, SDKs, and Suppliers

Camera, photo-library, microphone, location, notification, and similar permissions are requested by scenario only for actual functions and to the minimum extent necessary. Refusing a non-essential permission does not affect other basic functions. An SDK, plug-in, or external supplier may process production personal information only after its production configuration, contracting entity, data fields, processing location, and contractual duties have been verified and the required notice has been provided.

See the current public Supplier and Subprocessor List. A supplier that is not listed or has not been verified may not process production personal information.

5. Artificial Intelligence and Automated Processing

Anonymization means irreversible processing, supported by a re-identification risk assessment, after which a specific person cannot be identified and the data cannot be restored; the resulting data is no longer personal information. De-identified data may still be re-identified and remains personal information; de-identified Organization-Controlled Data remains subject to the DPA and the Organization's instructions.

Training a model with identifiable personal information, sensitive personal information, or Children's personal information requires an independent lawful basis, the applicable separate notice, separate consent or Guardian consent, and a convenient opt-out mechanism. Service terms, a general DPA instruction, or de-identification alone is not sufficient.

6. Your Rights

You may lawfully request access, a copy, correction, supplementation, deletion, an explanation of processing rules, withdrawal of consent-based processing, account deletion, and the applicable rights concerning automated decision-making. For Organization-Controlled Data, contact the relevant Organization first; we will assist within the scope of the DPA. We generally respond within 15 business days after identity verification, unless law provides otherwise.

7. Full Texts and Contact Channels

  • Privacy Policy
  • Children's Personal Information Protection Policy
  • Organization Data Processing Agreement
  • Supplier and Subprocessor List
  • General privacy and dedicated Children's personal information channel: support@growing-x.com (please include “Children's Personal Information” in the subject line for Child-related matters)

(End)

Back to top ↑
GrowingX

Digital operations platform for organizations across industries

LEGALPrivacy PolicyTerms of ServiceData Processing
SUPPORTSupport Centersupport@growing-x.com
© 2018–2026 Chengdu Hanxi Technology Co., Ltd.成都瀚熙科技有限责任公司蜀ICP备2021013585号