[{"data":1,"prerenderedAt":694},["ShallowReactive",2],{"legal-en-privacy-policy":3},{"id":4,"title":5,"body":6,"description":12,"extension":685,"meta":686,"navigation":687,"path":688,"seo":689,"stem":690,"subTitle":691,"updatedAt":692,"__hash__":693},"content/privacy-policy.md","NXAI Group Privacy Policy",{"type":7,"value":8,"toc":622},"minimark",[9,13,18,188,191,194,197,206,209,212,215,223,226,229,243,246,249,252,263,266,269,272,280,288,291,294,300,303,306,309,312,315,318,321,324,327,333,336,342,345,348,351,354,357,360,363,366,369,375,378,382,385,388,391,394,397,400,406,409,414,417,420,423,432,435,443,446,449,452,455,458,461,464,467,481,484,487,490,493,496,507,510,513,516,519,522,525,528,531,534,537,540,543,551,554,557,560,563,566,569,572,575,578,581,584,587,592,595,598,601,604,607,610,616,619],[10,11,12],"p",{},"NXAI takes the protection of your personal data seriously. We are a Singapore-headquartered communications cloud provider serving customers around the world, and we provide privacy safeguards and rights consistent with the law of the country/region where you are located. This Policy explains how we collect, use, share, and protect personal data in connection with the NXCLOUD and NXLINK Services. We encourage you to read this Policy in full, together with the Annex applicable to your location.",[10,14,17],{"className":15},[16],"note","Note: This document consolidates the three previously separate documents — the NXAI Group Privacy Policy, the NXCLOUD Privacy Policy, and the NXLINK Privacy Policy. Upon official publication, this document supersedes all three and applies uniformly to the NXCLOUD and NXLINK products. The main body (Chapters 1–16) sets out rules applicable to all Services; Annexes 1–5 supplement these rules for specific countries/regions, describing additional rights and obligations under local law. The main body and the Annexes apply together: if you are located in a country/region covered by an Annex, that Annex prevails over the main body to the extent of any inconsistency. Article numbers, authority names and timeframes cited in the Annexes reflect publicly available legal information current as of the effective date of this Policy; where the underlying law is later amended or superseded, the law then in force in the relevant jurisdiction shall govern. This Policy is provided to help you understand your rights and our obligations and does not constitute legal advice.",[19,20,24,28,80,83,113,116,133,136,155,158,175,178],"nav",{"className":21,"ariaLabel":23},[22],"policy-toc","Table of Contents",[25,26,23],"h2",{"id":27},"table-of-contents",[29,30,31,35,38,41,44,47,50,53,56,59,62,65,68,71,74,77],"ol",{},[32,33,34],"li",{},"Chapter 1 — Introduction: Who We Are",[32,36,37],{},"Chapter 2 — Scope and Roles: Controller and Processor",[32,39,40],{},"Chapter 3 — Information We Collect and Purposes of Use",[32,42,43],{},"Chapter 4 — Disclosure of Personal Data",[32,45,46],{},"Chapter 5 — Cookies and Similar Technologies",[32,48,49],{},"Chapter 6 — Third-Party Service Providers and Their Services",[32,51,52],{},"Chapter 7 — Where We Store Personal Data and Cross-Border Transfers (General)",[32,54,55],{},"Chapter 8 — Data Retention",[32,57,58],{},"Chapter 9 — Security Measures and Certifications",[32,60,61],{},"Chapter 10 — Children's Privacy",[32,63,64],{},"Chapter 11 — Your Rights (General Baseline)",[32,66,67],{},"Chapter 12 — Data Breach Notification",[32,69,70],{},"Chapter 13 — Automated Decision-Making",[32,72,73],{},"Chapter 14 — Governing Law and Dispute Resolution",[32,75,76],{},"Chapter 15 — Changes to This Policy",[32,78,79],{},"Chapter 16 — Contact Us",[10,81,82],{},"Annex 1 — European Union / European Economic Area and United Kingdom (GDPR / UK GDPR)",[84,85,86,89,92,95,98,101,104,107,110],"ul",{},[32,87,88],{},"Scope",[32,90,91],{},"Legal Bases for Processing",[32,93,94],{},"Your Rights",[32,96,97],{},"Exercising Your Rights",[32,99,100],{},"Cross-Border Transfers",[32,102,103],{},"Data Breach Notification",[32,105,106],{},"Right to Complain",[32,108,109],{},"Data Protection Officer",[32,111,112],{},"EU/UK Representatives",[10,114,115],{},"Annex 2 — Singapore (Personal Data Protection Act)",[84,117,118,120,123,125,127,130],{},[32,119,88],{},[32,121,122],{},"Consent and Exceptions",[32,124,94],{},[32,126,100],{},[32,128,129],{},"Mandatory Data Breach Notification",[32,131,132],{},"Complaints and Contact",[10,134,135],{},"Annex 3 — Hong Kong SAR (Personal Data (Privacy) Ordinance)",[84,137,138,140,143,146,149,152],{},[32,139,88],{},[32,141,142],{},"Six Data Protection Principles",[32,144,145],{},"Data Access and Correction Requests",[32,147,148],{},"Direct Marketing",[32,150,151],{},"Data Breach",[32,153,154],{},"Complaints",[10,156,157],{},"Annex 4 — Indonesia (Personal Data Protection Law No. 27 of 2022)",[84,159,160,162,164,167,169,171,173],{},[32,161,88],{},[32,163,94],{},[32,165,166],{},"Processing Principles and Legal Basis",[32,168,103],{},[32,170,100],{},[32,172,109],{},[32,174,154],{},[10,176,177],{},"Annex 5 — Chile",[84,179,180,182,185],{},[32,181,88],{},[32,183,184],{},"Current Law",[32,186,187],{},"Forthcoming Law",[25,189,34],{"id":190},"chapter-1-introduction-who-we-are",[10,192,193],{},"Welcome, and thank you for your interest in the suite of online services provided by NXCLOUD and NXLINK within the NXAI group, including our websites, networks, applications, APIs/SDKs, and supporting documentation (collectively, the \"Services\"). This Policy explains how NXCLOUD ASIA PTE. LTD., GLORY COMMUNICATIONS PTE. LTD., NX COMMUNICATIONS PTE. LTD., GLORY TECHNOLOGY (H.K) GROUP LIMITED, NXCLOUD B.V., and CONG TY TNHH NXCLOUD COMMUNICATIONS (together, \"NXAI\", \"we\", \"us\", or \"our\") collect, use, disclose, and protect personal data.",[10,195,196],{},"This Privacy Policy applies to our customers, prospective customers, customers' end users (including both direct and indirect users), visitors to our corporate websites, and recipients of our email communications. By using our Services or accessing our websites, you acknowledge and understand that NXAI may collect, use, and share your personal data in accordance with this Policy. If you do not agree with the terms of this Policy, you should not use our Services.",[10,198,199,200,205],{},"Our headquarters office address is Solaris, 1 Fusionopolis Walk #06-02, Singapore 138628. If you have questions about this Policy, you may contact our privacy team at ",[201,202,204],"a",{"href":203},"mailto:compliance@nxai.com","compliance@nxai.com",".",[10,207,208],{},"This Privacy Policy applies only to personal data processing activities occurring in the course of your use of NXCLOUD and NXLINK products and their related service functionalities. The relevant services are governed by the NXAI Group Terms of Service.",[25,210,37],{"id":211},"chapter-2-scope-and-roles-controller-and-processor",[10,213,214],{},"NXAI acts in different capacities depending on the context:",[84,216,217,220],{},[32,218,219],{},"When we collect personal data directly from you — for example, when you register for an account, visit our websites, or contact our support team — we act as the data controller.",[32,221,222],{},"When you, as a business customer, use our Services to communicate with your own end users (for example, sending SMS, voice, or WhatsApp messages through the NXLINK or NXCLOUD platform), we act as a data processor on your behalf, and you remain the data controller for your end users' personal data. Requests from your end users regarding their personal data should be directed to you as the controller; we will support you in responding to such requests in accordance with our Data Processing Agreement (DPA).",[25,224,40],{"id":225},"chapter-3-information-we-collect-and-purposes-of-use",[10,227,228],{},"We act as a data controller only in the following scenarios:",[29,230,231,234,237,240],{},[32,232,233],{},"When you register for an account. We collect: name, business email address, company name, country/region, and account password; if you register through NXLINK, we also collect a mobile phone number. This information is used to create and manage your account, complete registration, provide access to the Services, and send you service-related notifications and security alerts.",[32,235,236],{},"When you communicate with our customer support. We may request: name, email address, company name, country/region (and, for NXLINK, mobile phone number). We use this information to identify and respond to your inquiries and provide necessary communication support, based on our legitimate interests in responding to your proactive request.",[32,238,239],{},"Communication data processed on behalf of business customers. When you, as a business customer, use the Services to send communications to your end users, we process the related communication data on your instructions, acting as a processor (see Chapter 2).",[32,241,242],{},"Usage and technical data. Log data, IP address, device and browser information, collected automatically when you use our websites or Services.",[10,244,245],{},"We do not use the above information for marketing or personalized advertising purposes. If we intend to expand the scope of use in the future, we will obtain your consent separately in accordance with applicable law.",[25,247,43],{"id":248},"chapter-4-disclosure-of-personal-data",[10,250,251],{},"We take the security of your personal data seriously and will not disclose it to any third party without your authorization or a valid legal basis. We do not sell your personal data. We may share or disclose personal data only in the following circumstances:",[84,253,254,257,260],{},[32,255,256],{},"Cloud infrastructure service providers who host and process data on our behalf.",[32,258,259],{},"Professional advisors, auditors, and regulators, where required by law.",[32,261,262],{},"Legal disclosure: in accordance with applicable laws, court judgments, administrative orders, or in response to compliance requests from regulators (such as data protection authorities or telecommunications regulators), strictly in accordance with legal procedure and limited to the necessary scope.",[10,264,265],{},"Other than as described above, we do not sell, transfer, publish, or otherwise make your personal data available to any third party, including business partners, advertisers, or third-party content providers.",[25,267,46],{"id":268},"chapter-5-cookies-and-similar-technologies",[10,270,271],{},"Our websites use cookies and similar technologies for essential, functional, and analytics/advertising purposes:",[84,273,274,277],{},[32,275,276],{},"Session cookies disappear automatically when you close your browser or shut down your device;",[32,278,279],{},"Persistent cookies remain stored on your device after it is powered off.",[10,281,282,283,205],{},"Cookies on our websites fall into three categories: required, functional, and advertising cookies. You can manage your preferences at any time using the \"Cookie Preferences\" tool at the bottom-right of our websites. For further detail, see our Cookie Policy at ",[201,284,285],{"href":285,"rel":286},"https://www.nxai.com/legal/cookie-policy",[287],"nofollow",[25,289,49],{"id":290},"chapter-6-third-party-service-providers-and-their-services",[10,292,293],{},"We engage cloud infrastructure service providers to host and process personal data on our behalf, as described in Chapter 7. Other than infrastructure sub-processors engaged strictly to provide the Services, we do not integrate independent third-party service providers or embed third-party content in our Services, nor do we share your personal data with third parties for their own independent purposes. Should we introduce third-party services or functionalities in the future — such as third-party SDKs, analytics tools, or external links — we will provide separate notice on the relevant pages and obtain consent where required.",[10,295,296,297,299],{},"We maintain a current list of sub-processors, naming each sub-processor, the processing activity it performs, and its location. Business customers may request this list at ",[201,298,204],{"href":203},". If we intend to add or replace a sub-processor, we will notify business customers in the manner and within the advance notice period set out in the applicable Data Processing Agreement (DPA), and provide an opportunity to object within the agreed period.",[25,301,52],{"id":302},"chapter-7-where-we-store-personal-data-and-cross-border-transfers-general",[10,304,305],{},"NXAI operates service sites (\"Service Sites\") through a number of third-party cloud infrastructure providers across multiple countries and regions, currently including Hong Kong, Singapore, Indonesia, Chile, and the European Union, and may add or adjust such Service Sites from time to time. Personal data relating to a particular service is generally stored and processed within the Service Site corresponding to that service, in order to meet applicable data localization requirements.",[10,307,308],{},"To provide the Services and support global operations, personal data may be transferred across countries or regions within the NXAI group, including from the Service Site where it is stored to other NXAI group companies or personnel, for purposes such as operational support and customer service. Such intra-group transfers are governed by NXAI's intra-group data transfer agreement, under which all NXAI group companies must handle personal data in accordance with the standards set out in this Policy.",[10,310,311],{},"If you are located in the European Union/EEA, Singapore, Hong Kong, Indonesia, or Chile, additional statutory requirements and safeguards for cross-border transfers are set out in Annexes 1 through 5.",[25,313,55],{"id":314},"chapter-8-data-retention",[10,316,317],{},"We retain personal data only for as long as necessary to provide the Services and comply with our legal obligations. Except where applicable law or a regulatory requirement mandates a longer retention period, our standard retention period is 2 years. Certain categories of data, such as system and security logs, may be subject to different retention periods under our internal data retention schedule. Invoices, accounting vouchers, and other accounting, tax, and audit records may be retained separately for significantly longer periods, as required for compliance, tax filing, or audit purposes. If you delete or deactivate your account, we will cease providing the associated services and delete related personal data, except where retention is required by applicable law.",[25,319,58],{"id":320},"chapter-9-security-measures-and-certifications",[10,322,323],{},"We maintain technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and multi-factor authentication for systems handling customer data, and provide employees with information security and privacy training. NXAI holds ISO/IEC 27001 (Information Security Management), ISO/IEC 27701 (Privacy Information Management), and ISO 9001 (Quality Management) certifications, each subject to periodic independent audit and recertification. While we are committed to protecting your personal data, no security measure is completely foolproof.",[25,325,61],{"id":326},"chapter-10-childrens-privacy",[10,328,329,330,332],{},"Our Services are primarily intended for adult, business-context users. We do not intentionally target or collect personal data from minors. If you are a minor under the age of 18, please use our Services or provide personal data only after obtaining consent from your parent or legal guardian. If we become aware that we have inadvertently collected personal data from a minor without verifiable parental consent, we will verify the circumstances and delete the relevant data as soon as possible. Please contact us at ",[201,331,204],{"href":203}," if you believe this may have occurred.",[25,334,64],{"id":335},"chapter-11-your-rights-general-baseline",[10,337,338,339,341],{},"Subject to applicable law, you may have the right to access, correct, delete, restrict, or port your personal data, and to withdraw consent where processing is based on consent. To exercise these rights, contact us at ",[201,340,204],{"href":203},". We aim to respond to verified requests within 30 calendar days. You may have more specific or broader rights and complaint channels under the law of your country/region — see Annexes 1 through 5.",[25,343,67],{"id":344},"chapter-12-data-breach-notification",[10,346,347],{},"In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected customers within 48 hours and, where required by law, notify the relevant regulator without undue delay. Certain jurisdictions impose mandatory statutory notification deadlines and recipients — see the applicable Annex.",[25,349,70],{"id":350},"chapter-13-automated-decision-making",[10,352,353],{},"NXAI does not currently make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. If this changes, we will update this Policy to describe the logic involved and your right to request human review.",[25,355,73],{"id":356},"chapter-14-governing-law-and-dispute-resolution",[10,358,359],{},"This Policy, including its formation, interpretation, performance, and any disputes or claims arising out of or in connection with it (including non-contractual disputes or claims), is governed by the laws of Singapore, without regard to conflict of law principles. Disputes shall first be resolved through good faith negotiation; if unresolved within thirty (30) calendar days, either party may refer the dispute to arbitration administered by the Singapore International Arbitration Centre (SIAC), seated in Singapore, conducted in English, with the award final and binding. This clause does not affect your right to lodge a complaint with your local regulator or bring proceedings before a competent local court under the law of your jurisdiction (see Annexes 1–5).",[25,361,76],{"id":362},"chapter-15-changes-to-this-policy",[10,364,365],{},"We may update this Policy from time to time. Material changes will be notified through our websites or by email at least 30 calendar days before they take effect; updates relating only to product or feature functionality may take effect immediately upon posting. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.",[25,367,79],{"id":368},"chapter-16-contact-us",[10,370,371,372,374],{},"If you have any questions, comments, or complaints about this Policy, please contact us at ",[201,373,204],{"href":203}," or +65-31292899.",[25,376,82],{"id":377},"annex-1-european-union-european-economic-area-and-united-kingdom-gdpr-uk-gdpr",[379,380,88],"h3",{"id":381},"scope",[10,383,384],{},"This Annex applies to data subjects located in the EU, EEA, or UK, or where NXAI offers services to, or monitors the behaviour of, data subjects in the EU/EEA/UK. It supplements the disclosures required under Regulation (EU) 2016/679 (\"GDPR\") and the UK GDPR under the UK's Data Protection Act 2018 (as amended).",[379,386,91],{"id":387},"legal-bases-for-processing",[10,389,390],{},"(GDPR Art. 6) We process your personal data based on: performance of a contract with you (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)); our legitimate interests, including providing and improving the Services and safeguarding network and information security (Art. 6(1)(f)); and, where applicable, your consent (Art. 6(1)(a)). We do not currently process special category data under GDPR Art. 9.",[379,392,94],{"id":393},"your-rights",[10,395,396],{},"(GDPR Chapter III) You have the right to: transparency and information (Arts. 13, 14); access (Art. 15); rectification (Art. 16); erasure / \"right to be forgotten\" (Art. 17); restriction of processing (Art. 18); data portability (Art. 20); object to processing, including processing based on legitimate interests and for direct marketing (Art. 21); and not be subject to a decision based solely on automated processing, including profiling (Art. 22).",[379,398,97],{"id":399},"exercising-your-rights",[10,401,402,403,405],{},"Contact ",[201,404,204],{"href":203},". We will respond within one month of a verified request; if the request is complex, we may extend this by up to two further months under Art. 12(3), notifying you of the reason.",[379,407,100],{"id":408},"cross-border-transfers",[10,410,411,412,205],{},"(GDPR Chapter V, Arts. 44–49) Where we transfer your personal data from the EEA/UK to a country not subject to an adequacy decision by the European Commission/UK Government (including the Service Site locations described in Chapter 7), we rely on Art. 46 transfer mechanisms such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Agreement/Addendum, supplemented by additional safeguards where necessary. You may request a copy of the relevant transfer mechanism at ",[201,413,204],{"href":203},[379,415,103],{"id":416},"data-breach-notification",[10,418,419],{},"(GDPR Arts. 33, 34) We will notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in a risk to your rights and freedoms, and will notify you without undue delay where the breach is likely to result in a high risk to you.",[379,421,106],{"id":422},"right-to-complain",[10,424,425,426,431],{},"(GDPR Art. 77) You have the right to lodge a complaint with the data protection supervisory authority of your habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is available from the European Data Protection Board (EDPB); UK users may contact the Information Commissioner's Office (ICO, ",[201,427,430],{"href":428,"rel":429},"http://www.ico.org.uk",[287],"www.ico.org.uk",").",[379,433,109],{"id":434},"data-protection-officer",[10,436,437,438,442],{},"Given the scale and nature of NXAI's personal data processing, NXAI has appointed a Data Protection Officer under GDPR Art. 37. If you have any questions about our processing of personal data, or wish to contact the Data Protection Officer directly, please email ",[201,439,441],{"href":440},"mailto:markcui@nxai.com","markcui@nxai.com"," (Attn: Mark Cui).",[379,444,112],{"id":445},"euuk-representatives",[10,447,448],{},"NXAI Group has an operating establishment in the European Union — NXCLOUD B.V., incorporated in the Netherlands. Because NXAI accordingly has an establishment in the Union in respect of EU/EEA data subjects, GDPR Art. 27 (which applies only to controllers and processors not established in the Union) does not require NXAI to appoint a separate EU representative. As the UK is no longer part of the EU, this Netherlands establishment does not by itself satisfy any corresponding UK requirement; if NXAI is required to appoint a UK representative under the UK GDPR, we will do so in accordance with law and publish contact details via an update to this Policy.",[25,450,115],{"id":451},"annex-2-singapore-personal-data-protection-act",[379,453,88],{"id":454},"scope-1",[10,456,457],{},"This Annex applies to personal data collected, used, or disclosed under Singapore's Personal Data Protection Act 2012, as amended (the \"PDPA\"), including data processed by NXAI's Singapore-registered entities and data collected within Singapore.",[379,459,122],{"id":460},"consent-and-exceptions",[10,462,463],{},"(PDPA ss. 13–17) Except where a statutory exception applies (e.g., business contact information, legal exemptions), our collection, use, and disclosure of personal data is based on your consent or an applicable statutory exception.",[379,465,94],{"id":466},"your-rights-1",[84,468,469,472,475,478],{},[32,470,471],{},"Right of access (s. 21): You may request access to the personal data we hold about you and how it has been used or disclosed within the past year.",[32,473,474],{},"Right to correction (s. 22): You may request correction of inaccurate or incomplete data.",[32,476,477],{},"Right to withdraw consent (s. 16): You may withdraw previously given consent at any time; withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.",[32,479,480],{},"Data portability (ss. 26N–26U): Subject to prescribed conditions, you may request that certain personal data be transmitted to another organisation in a structured, commonly used electronic format.",[379,482,100],{"id":483},"cross-border-transfers-1",[10,485,486],{},"(PDPA s. 26; Personal Data Protection Regulations 2021, as updated by the Personal Data Protection (Amendment) Regulations 2026) Before transferring personal data outside Singapore, we ensure the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA. This is satisfied where, among other things: the recipient holds a valid Global Cross-Border Privacy Rules (Global CBPR, the successor to the APEC CBPR system) certification, or, as a data intermediary, a valid Global Privacy Recognition for Processors (Global PRP) certification; the recipient has entered into a contractual arrangement with us containing comparable protection obligations; or the recipient is bound by binding corporate rules.",[379,488,129],{"id":489},"mandatory-data-breach-notification",[10,491,492],{},"(PDPA ss. 26A–26E, Part VIA) In the event of a \"notifiable data breach\" (one likely to result in significant harm to affected individuals, or of a scale meeting the prescribed threshold), we will assess the breach promptly and, where notifiable, notify the Personal Data Protection Commission (PDPC) within 3 calendar days, and notify affected individuals as soon as practicable where significant harm is likely.",[379,494,132],{"id":495},"complaints-and-contact",[10,497,498,499,503,504,506],{},"You may lodge a complaint with the Personal Data Protection Commission of Singapore: ",[201,500,501],{"href":501,"rel":502},"https://www.pdpc.gov.sg",[287],". For general requests, contact ",[201,505,204],{"href":203},"; we aim to respond to verified requests within the reasonable period prescribed by the PDPA, typically within 30 calendar days.",[25,508,135],{"id":509},"annex-3-hong-kong-sar-personal-data-privacy-ordinance",[379,511,88],{"id":512},"scope-2",[10,514,515],{},"This Annex applies to personal data collected, held, processed, or used under Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486, the \"PDPO\").",[379,517,142],{"id":518},"six-data-protection-principles",[10,520,521],{},"(Schedule 1) We handle your personal data in accordance with the six Data Protection Principles under PDPO Schedule 1: purpose and manner of collection (DPP1); accuracy and retention (DPP2); use limited to the collection purpose or a directly related purpose (DPP3); appropriate security safeguards (DPP4); openness and transparency of policies and practices (DPP5); and your right of access to and correction of personal data (DPP6).",[379,523,145],{"id":524},"data-access-and-correction-requests",[10,526,527],{},"(PDPO ss. 18–24) You may make a data access request to confirm whether we hold your personal data and obtain a copy of it, and a data correction request for inaccurate data. We will respond within 40 days of a valid request (providing reasons if refused); we may charge a reasonable fee for handling access requests.",[379,529,148],{"id":530},"direct-marketing",[10,532,533],{},"We will not use your personal data for direct marketing, or provide it to others for that purpose, without your prior consent (PDPO s. 35C).",[379,535,151],{"id":536},"data-breach",[10,538,539],{},"The PDPO does not currently impose a mandatory data breach notification requirement, though the Office of the Privacy Commissioner for Personal Data (\"PCPD\") recommends voluntary notification of the PCPD and affected individuals as soon as practicable following a breach, and we follow the PCPD's Guidance on Data Breach Handling and Notification. The Hong Kong Government has been reviewing proposals to introduce mandatory breach notification and administrative fines; we will update this Annex if such amendments come into force.",[379,541,154],{"id":542},"complaints",[10,544,545,546,205],{},"You may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong: ",[201,547,550],{"href":548,"rel":549},"http://www.pcpd.org.hk",[287],"www.pcpd.org.hk",[25,552,157],{"id":553},"annex-4-indonesia-personal-data-protection-law-no-27-of-2022",[379,555,88],{"id":556},"scope-3",[10,558,559],{},"This Annex applies to personal data processed under Indonesia's Law No. 27 of 2022 on Personal Data Protection (the \"PDP Law\"), including data collected within Indonesia and data collected outside Indonesia that produces legal effects for, or relates to, Indonesian data subjects. Indonesia's principal implementing regulation for the PDP Law — Government Regulation No. 33 of 2026 (\"GR 33/2026\"), promulgated on 16 July 2026 with a six-month transition period and full enforcement from 16 January 2027 — has been issued and sets out more detailed rules on matters including data breach notification, procedures for exercising data subject rights, and cross-border transfers. This Annex will continue to be updated to reflect the requirements of GR 33/2026.",[379,561,94],{"id":562},"your-rights-2",[10,564,565],{},"(PDP Law Arts. 5–16) You have the right to: information about processing (Art. 5); access to information about processing (Art. 6); rectification (Art. 7); to stop processing and request erasure (Arts. 8–9); to withdraw consent (Art. 9); to object to decisions based solely on automated processing, including profiling (Art. 10); to delay or restrict processing (Art. 11); to sue for and obtain compensation for violations (Art. 12); and to data portability (Art. 13).",[379,567,166],{"id":568},"processing-principles-and-legal-basis",[10,570,571],{},"We process your personal data on the legal bases set out in Art. 20 of the PDP Law, including explicit consent, contractual necessity, compliance with legal obligations, and legitimate interests.",[379,573,103],{"id":574},"data-breach-notification-1",[10,576,577],{},"(PDP Law Art. 46; implementing rules under GR 33/2026) In the event of a personal data breach, we will provide written notice to affected data subjects and the competent Indonesian personal data protection authority within 3 x 24 hours (72 hours) of reasonably confirming, based on supporting evidence such as system logs or forensic investigation findings, that a personal data protection failure has in fact occurred. The 72-hour period runs from that confirmed determination, not from the point of initial suspicion.",[379,579,100],{"id":580},"cross-border-transfers-2",[10,582,583],{},"(PDP Law Arts. 55–56) When transferring personal data outside Indonesia, we will, in order of priority: (a) confirm the recipient country provides a level of personal data protection equivalent to or higher than Indonesia's; (b) rely on adequate safeguards under a binding international agreement; or (c) where neither is available, obtain your explicit consent as the basis for transfer, together with any other conditions required by the competent authority.",[379,585,109],{"id":586},"data-protection-officer-1",[10,588,589,590,205],{},"NXAI has appointed Mark Cui as the group's data protection officer, fulfilling the requirements of both GDPR Art. 37 and PDP Law Art. 53. If you have any questions about our processing of personal data, please email ",[201,591,441],{"href":440},[379,593,154],{"id":594},"complaints-1",[10,596,597],{},"You may submit a complaint to Indonesia's Personal Data Protection Authority (Lembaga Pelindungan Data Pribadi).",[25,599,177],{"id":600},"annex-5-chile",[379,602,88],{"id":603},"scope-4",[10,605,606],{},"This Annex applies to personal data processed under the laws of Chile.",[379,608,184],{"id":609},"current-law",[10,611,612,613,615],{},"As of the date of this Policy, the primary data protection law in force in Chile is Law No. 19,628 on the Protection of Private Life (Ley sobre Protección de la Vida Privada), as amended. Under the current law, you have \"ARCO rights\" — access (Acceso), rectification (Rectificación), cancellation/erasure (Cancelación), and objection (Oposición) — which you may exercise via ",[201,614,204],{"href":203},". Chile does not currently have a dedicated data protection authority; disputes are handled by the competent ordinary courts.",[379,617,187],{"id":618},"forthcoming-law",[10,620,621],{},"Chile has enacted Law No. 21,719 on Personal Data Protection, which will enter into full force on December 1, 2026. Upon entry into force, this law will: (a) establish a new independent regulator, the Personal Data Protection Agency (Agencia de Protección de Datos Personales, \"APDP\"); (b) introduce GDPR-aligned processing principles, data subject rights, and cross-border transfer rules; and (c) introduce mandatory data breach notification and administrative penalties. This Annex will be updated around the entry into force of the new law to accurately reflect the applicable provisions, deadlines, and regulator contact details then in effect. Until then, in the event of any inconsistency with the main body of this Policy, the current Law No. 19,628 and this Annex prevail.",{"title":623,"searchDepth":624,"depth":624,"links":625},"",2,[626,627,628,629,630,631,632,633,634,635,636,637,638,639,640,641,642,643,655,663,671,680],{"id":27,"depth":624,"text":23},{"id":190,"depth":624,"text":34},{"id":211,"depth":624,"text":37},{"id":225,"depth":624,"text":40},{"id":248,"depth":624,"text":43},{"id":268,"depth":624,"text":46},{"id":290,"depth":624,"text":49},{"id":302,"depth":624,"text":52},{"id":314,"depth":624,"text":55},{"id":320,"depth":624,"text":58},{"id":326,"depth":624,"text":61},{"id":335,"depth":624,"text":64},{"id":344,"depth":624,"text":67},{"id":350,"depth":624,"text":70},{"id":356,"depth":624,"text":73},{"id":362,"depth":624,"text":76},{"id":368,"depth":624,"text":79},{"id":377,"depth":624,"text":82,"children":644},[645,647,648,649,650,651,652,653,654],{"id":381,"depth":646,"text":88},3,{"id":387,"depth":646,"text":91},{"id":393,"depth":646,"text":94},{"id":399,"depth":646,"text":97},{"id":408,"depth":646,"text":100},{"id":416,"depth":646,"text":103},{"id":422,"depth":646,"text":106},{"id":434,"depth":646,"text":109},{"id":445,"depth":646,"text":112},{"id":451,"depth":624,"text":115,"children":656},[657,658,659,660,661,662],{"id":454,"depth":646,"text":88},{"id":460,"depth":646,"text":122},{"id":466,"depth":646,"text":94},{"id":483,"depth":646,"text":100},{"id":489,"depth":646,"text":129},{"id":495,"depth":646,"text":132},{"id":509,"depth":624,"text":135,"children":664},[665,666,667,668,669,670],{"id":512,"depth":646,"text":88},{"id":518,"depth":646,"text":142},{"id":524,"depth":646,"text":145},{"id":530,"depth":646,"text":148},{"id":536,"depth":646,"text":151},{"id":542,"depth":646,"text":154},{"id":553,"depth":624,"text":157,"children":672},[673,674,675,676,677,678,679],{"id":556,"depth":646,"text":88},{"id":562,"depth":646,"text":94},{"id":568,"depth":646,"text":166},{"id":574,"depth":646,"text":103},{"id":580,"depth":646,"text":100},{"id":586,"depth":646,"text":109},{"id":594,"depth":646,"text":154},{"id":600,"depth":624,"text":177,"children":681},[682,683,684],{"id":603,"depth":646,"text":88},{"id":609,"depth":646,"text":184},{"id":618,"depth":646,"text":187},"md",{},true,"/privacy-policy",{"title":5,"description":12},"privacy-policy",null,"Last updated: September 9, 2026","GrRW7gIHtev0_-UZHfBUNFe3ma54QM38yE7QUevB0C8",1789465274527]