Important Notice
Document Version: 2026.08.16.1
Last Updated: August 16, 2026
Effective Date: August 16, 2026
Current status: Engineering compliance draft pending external counsel's written sign-off on this exact version and SHA-256, and pending verification of production supplier facts. This document is not lawyer-approved.
This page lists only external suppliers that have completed verification of production activation, contracting legal entity, product, processing purpose, data categories, processing location, duration, cross-border position, and contractual duties, and that may process personal information on behalf of Chengdu Hanxi Technology Co., Ltd. A code dependency, optional adapter, test account, configuration template, procurement candidate, or brand name does not establish production processing.
1. Currently Verified Public List
As of the Effective Date of this version, there are no verified items eligible for public listing.
Accordingly, an external supplier, SDK, plug-in, or service interface that is not listed on this page or remains under verification may not receive, access, store, transmit, or otherwise process production personal information. A dependency, placeholder credential, test configuration, or candidate solution in the codebase does not relax this gate.
2. Verification Standard for Listing
A supplier may be listed only when reviewable evidence establishes all of the following:
- actual production activation and production data flows, rather than testing or reserved configuration only;
- the contracting legal entity, specific product, processing role, and onward subcontracting arrangements;
- data subjects, data fields, purposes, means, locations, frequency, and duration;
- sensitive personal information, Children's personal information, and cross-border processing, with applicable assessments, notices, and consents completed;
- contractual purpose limitation, minimization, confidentiality, security, incident notice, audit assistance, return/deletion, and termination/exit duties; and
- written approval by the procurement/business owner, information security, privacy compliance, and legal functions.
3. Addition, Replacement, and Objection
Before adding or replacing a subprocessor, we will in principle give at least 30 calendar days' prior notice through this page, an in-product notice, or the Organization's designated contact. The notice will identify the verified legal entity, product, purpose, data categories, processing location, and effective date. An Organization Customer may object in writing on reasonable data-protection grounds within 15 calendar days after delivery of the notice.
The parties will in good faith assess cessation of the affected processing, a verified alternative, or additional safeguards. If the issue cannot reasonably be resolved before the effective date, the Customer may stop instructions for the affected part or terminate the affected Service under the DPA. If an urgent security risk or legal requirement prevents full advance notice, we will notify the Customer as early as legally permitted and explain the reason.
4. Relationship with Other Documents
The authorization, oversight, responsibility, and audit rules for subprocessors are set out in the Organization Data Processing Agreement. Supplier disclosures for activities in which Hanxi acts as a personal information handler are set out in the Privacy Policy. A commercial Order may not implicitly add a subprocessor or lower the supplier-admission requirements in the DPA.
(End)
Back to top ↑