HaiToken Privacy Policy
Last Updated: 2026-07-26 Effective Date: 2026-07-26 Data User: LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司 Version Status: Published Version
Reading Guide
Please pay particular attention to the bold headings and the numbered clauses. This Privacy Policy explains how HaiToken collects, holds, processes, uses, discloses, transfers and protects personal data. Section 3 identifies what HaiToken is (a technical intermediary that routes requests to third-party Providers). Section 5 explains our position on prompts, completions and Customer API Data, including that our default configuration does not retain or store Customer API Data beyond what is operationally necessary. Section 7 explains our position on training. Section 8 lists the third-party Providers and their privacy policies. Section 21 contains additional disclosures under the GDPR and US state laws. If the English and Chinese texts differ, the English text prevails.
Language
This Privacy Policy is prepared in English and Chinese. Both texts are intended to have legal effect. If there is any inconsistency, ambiguity or conflict between the English text and the Chinese text, the English text prevails, unless HaiToken expressly states otherwise in writing.
1. Introduction
This Privacy Policy explains how LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司 ("HaiToken", "we", "us") collects, holds, processes, uses, discloses, transfers and protects personal data in connection with the HaiToken website, console, API, unified model gateway, routing services, usage monitoring, enterprise administration, support and related services (the "Services").
HaiToken serves Customers located outside mainland China who meet the eligibility requirements of the Service Agreement, including individual Customers, enterprise Customers, developers and organizations. Individual Customers must be at least eighteen (18) years of age. The Services are not offered to, and must not be used by or for the benefit of, any individual or entity located in, established in, ordinarily resident in, or accessing the Services from mainland China. The Services are not directed to Children. In this Privacy Policy, "Child" means any individual under eighteen (18) years of age, or any older individual treated as a minor under the laws applicable to that individual.
This Privacy Policy does not apply to the privacy practices of third-party model Providers, infrastructure providers, integrations or services not controlled by HaiToken. This Privacy Policy should be read together with the HaiToken Service Agreement and, where applicable, the Data Processing Agreement ("DPA").
2. Who We Are and Our Role
For personal data that HaiToken collects and uses for its own business purposes—such as account management, website operation, billing management, security, customer support, marketing communications and legal compliance—LDCY TECH HK LIMITED acts as a data user under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO").
For Customer API Data submitted through the Services by or on behalf of Customers, the Customer generally determines the purposes and means of processing. HaiToken generally acts as a data processor or service provider processing that data on behalf of the Customer, subject to the Service Agreement, this Privacy Policy and the DPA.
To the extent necessary for security, anti-fraud, abuse detection, billing, legal requests, compliance, Service integrity and enforcement of rights, HaiToken may also process limited information as an independent data user.
3. Data Covered by This Policy
HaiToken is a technical intermediary and routing agent. It routes Customer Inputs to third-party Providers and returns responses; it does not own, operate, train or control the underlying models. This Privacy Policy covers:
- Account Data: information about the Customer organization, Administrators, Authorized Users and contacts.
- Service Metadata: technical, usage, routing, billing, security and audit records generated by use of the Services.
- Customer API Data: prompts, inputs, conversation messages, files, images, audio, completions, outputs, training materials, fine-tuning materials, evaluation materials and other content submitted to, processed by, or returned through the API.
- Support Data: information provided in support tickets, emails, calls, chat messages, documentation requests and feedback.
- Website, Cookie and Analytics Data: information collected through our website, console, cookies, pixels and analytics tools.
- Security and Enforcement Data: logs, records, evidence and technical signals used to protect the Services, investigate abuse and enforce legal rights.
4. Information We Collect
We may collect the following categories of information:
- Account and organization information: name, business email, company name, job title, role, department, organization settings, billing contacts, legal contacts and support contacts.
- Authentication and access information: login records, password or authentication-method metadata, API Key identifiers, token identifiers, permission settings, Administrator actions, IP addresses, device identifiers and session information.
- Usage and billing metadata: timestamps, model identifiers, Provider identifiers, endpoints, token counts, request counts, latency, region, routing, status codes, error codes, fees, account balance, usage allowances, invoice records, subscription or plan information and budget events.
- Customer API Data: prompts, files, conversation messages, inputs, outputs, training or fine-tuning materials and associated logs processed through the Services, subject to the seven (7) day rolling retention position and exceptions described below.
- Support and communication information: information, attachments, screenshots, logs or other information you provide when contacting us.
- Website and analytics data: browser type, operating system, referring page, pages viewed, time spent, cookies, preferences and approximate location inferred from IP address.
- Security and enforcement information: abuse signals, anomaly scores, rate-limit events, suspected-scraping indicators, suspected model-extraction or distillation indicators, content-policy flags, Provider blocks, investigation records and legal-hold records.
We may receive information directly from you, your Authorized Users, systems using your API Keys, Providers, service providers, security tools, public sources, or third parties involved in investigating abuse or enforcing legal rights.
5. Prompts, Completions and Customer API Data
HaiToken's default operating configuration is that it does not retain or store Customer API Data beyond what is operationally necessary to provide the Services and to meet the purposes described in this Section. Following processing, HaiToken retains Customer API Data on a rolling basis for up to seven (7) days, including the associated prompt bodies, completion bodies, conversation records, files, outputs, training or fine-tuning materials submitted through the Services, and related logs. This rolling retention is used to check for unreasonable, abusive, unlawful or prohibited use; detect and investigate fraud, security incidents, scraping, unauthorized distillation, model extraction, output abuse or non-payment; resolve billing, routing, Provider and support issues; preserve and trace accountability; and enforce the Service Agreement and upstream terms.
After the seven (7) day rolling period expires, Customer API Data is automatically overwritten, deleted or de-identified in the ordinary course, unless one of the exceptions below applies. HaiToken may separately retain Service Metadata necessary for billing, security, routing, performance, audit, anti-fraud, abuse detection, customer support, compliance and enforcement.
Exceptions may apply where:
- the Customer enables logging, debugging, caching, replay, evaluation, dataset, fine-tuning, analytics or similar features;
- the Customer or an Authorized User includes prompts, outputs, files or logs in a support request or other communication with HaiToken;
- HaiToken reasonably believes it is necessary to preserve information for security, abuse detection, anti-fraud, non-payment, chargebacks, legal compliance, Provider requests, Service integrity, accountability or enforcement of rights;
- HaiToken reasonably suspects unauthorized distillation, model extraction, scraping, benchmarking for replication purposes, output abuse, infringement or other violation of the Service Agreement or upstream terms;
- retention is required by law, court order, tribunal, regulator, law-enforcement agency or valid legal process; or
- temporary processing, queuing, retries, caching, backups, telemetry or operational logging is technically necessary to provide and protect the Services.
Where an exception applies, HaiToken may generate, preserve, review, retain and disclose relevant Customer API Data, Service Metadata and related evidence for the relevant purposes for as long as reasonably necessary, including for investigation, enforcement, legal hold, dispute resolution, arbitration, litigation, regulatory response and applicable limitation periods, subject to the PDPO and other applicable law.
HaiToken screens and filters content to protect the Services and upstream resources. Although HaiToken does not retain or store Customer API Data beyond the purposes above, HaiToken reserves the right to screen and filter Inputs and Outputs, and to detect and block unlawful or prohibited content, in order to protect the Services, HaiToken's own systems, Providers and upstream resources, and to comply with upstream rules and legal requirements. This screening is a protective measure and does not change HaiToken's position that it does not retain Customer API Data for unrelated purposes.
Except as described in this Privacy Policy, the Service Agreement, the DPA, the Customer's configuration, upstream terms or applicable law, HaiToken does not sell, rent or knowingly disclose Customer API Data or Customer Privacy Data for unrelated commercial purposes. HaiToken does not disclose Customer API Data for third-party advertising.
6. How We Use Information
We use information to:
- provide, operate, route, maintain, monitor and improve the Services;
- authenticate users and manage accounts, API Keys, permissions, organizations and security settings;
- route Inputs to Providers and return Outputs;
- calculate usage, deduct account balance or usage allowances, issue invoices, collect fees and resolve billing disputes;
- detect, prevent and respond to security incidents, fraud, abuse, scraping, unauthorized distillation, model extraction, output abuse, non-payment and violations of our terms or upstream terms;
- preserve evidence, establish, exercise or defend legal rights, and conduct investigations, arbitration, litigation, regulatory responses or enforcement actions;
- provide customer support, troubleshooting, technical notices and Service communications;
- analyze Service performance, reliability, latency, cost, routing quality and aggregate usage trends;
- comply with legal, regulatory, accounting, tax, audit, sanctions, export-control and corporate obligations, including eligibility and geographic-restriction checks; and
- send product, security, administrative or marketing communications where permitted by law and user preferences.
Where the EU General Data Protection Regulation, the UK GDPR or similar laws apply, our legal bases may include performance of a contract, taking steps at your request before entering into a contract, our legitimate interests in providing, protecting, improving and enforcing the Services, compliance with legal obligations, consent where required, and the establishment, exercise or defense of legal claims.
7. Training and Product Improvement
By default, HaiToken does not use Customer API Data to train AI models or to create model-improvement datasets.
For the avoidance of doubt, HaiToken's seven (7) day rolling retention of Customer API Data for security, abuse detection, Service integrity, billing, support, accountability and enforcement purposes does not constitute Customer consent for HaiToken to use that data to train AI models or create model-improvement datasets.
Only where the Customer expressly opts in or signs a separate written agreement may HaiToken use Customer API Data for training, fine-tuning, evaluation datasets, model-improvement datasets or similar purposes. Any opt-in will describe the applicable scope, purpose, data categories and available controls. Unless a separate written agreement provides otherwise, the Customer may withdraw opt-in consent through available controls or by written notice, with effect on a going-forward basis only.
HaiToken may use aggregated or de-identified Service Metadata that does not identify a Customer or any individual to analyze and improve the Services, including routing quality, latency, reliability, pricing, capacity planning and security.
8. Third-Party Providers
The Services route Customer API Data to third-party Providers selected by the Customer, selected through the Customer's configuration, or selected by HaiToken's routing logic based on settings the Customer has enabled. Providers may process, retain, log, train on, transfer or otherwise handle data under their own terms and policies.
HaiToken does not control all Provider practices. The Customer is responsible for reviewing the upstream terms and privacy or data policies before using a model, and for selecting appropriate Providers based on the Customer's data sensitivity, industry, jurisdiction, confidentiality needs, regional requirements and compliance obligations.
For convenience, the privacy policies of certain third-party model Providers are listed below. This list is provided for convenience only, is not exhaustive, and may change from time to time. The Customer should review the current terms of the relevant Provider before use:
- OpenAI (GPT family): https://openai.com/policies/privacy-policy
- Anthropic (Claude family): https://www.anthropic.com/legal/privacy
- Google (Gemini family): https://policies.google.com/privacy
- Zhipu AI (GLM family): https://z.ai/privacy
- Moonshot (Kimi family): https://platform.moonshot.ai/privacy
- DeepSeek: https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
By using a Provider through HaiToken, the Customer authorizes HaiToken to disclose Customer API Data and related Service Metadata to that Provider to the extent necessary to route requests, return Outputs, bill usage, troubleshoot, enforce Provider requirements and provide the Services.
9. Cookies and Analytics
We may use cookies, local storage, pixels, SDKs and similar technologies for authentication, session management, security, anti-fraud, preferences, analytics, product improvement and communications.
Some cookies are necessary for the Services to operate. Other cookies or analytics technologies may be controlled through browser settings, console settings or consent tools where available. Disabling certain cookies may affect usability or functionality.
We may use analytics tools to understand website and console usage, diagnose issues, improve performance and measure communication effectiveness. We do not intentionally use analytics tools to collect prompt or completion bodies, unless the Customer provides such bodies through relevant features or support interactions.
Our current cookie deployment is described in the Cookie Policy. As of the effective date, HaiToken does not deploy performance or analytics cookies, marketing or advertising cookies, or third-party analytics, advertising, bot-management or customer-chat cookies in the online Services, unless the Cookie Policy has been updated and any necessary consent mechanism has been provided.
10. How We Share Information
We may disclose information to:
- Providers, to route requests, return Outputs, troubleshoot, comply with upstream terms and enforce restrictions;
- service providers and subprocessors, including cloud hosting, database, authentication, security, monitoring, analytics, customer support, email, billing management, professional advisors and business-operations vendors;
- Administrators and Authorized Users within the Customer organization, according to account permissions;
- regulators, law-enforcement agencies, courts, tribunals, government authorities, counterparties, Providers or advisors, where we believe disclosure is required or appropriate for legal compliance, enforcement, dispute resolution, security, anti-fraud or protection of rights;
- parties involved in a merger, acquisition, financing, reorganization, asset sale, due diligence or similar corporate transaction; and
- others as directed, consented to or instructed by the Customer.
Except as described in this Privacy Policy (including the corporate-transaction scenario in Section 10), the Service Agreement, the DPA, the Customer's configuration, upstream terms or applicable law, we do not sell or rent Customer API Data, nor do we disclose Customer API Data for third-party advertising or unrelated commercial purposes.
11. Retention and Deletion
We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, legal process, contract, audit, accounting, tax, security, dispute-resolution or enforcement needs.
Our current retention arrangements are as follows:
- Account Data and billing-management records: for the duration of the account and up to seven (7) years after account closure, where reasonably necessary for accounting, tax, audit, legal or dispute purposes.
- Service Metadata: up to twenty-four (24) months, unless a longer period is reasonably needed for security, abuse prevention, billing disputes, legal requests or compliance.
- Customer API Data, including prompt bodies, completion bodies, conversation records, files, outputs and training or fine-tuning materials submitted through the Services: rolling retention of up to seven (7) days after processing, after which it is automatically overwritten, deleted or de-identified in the ordinary course, unless a Section 5 exception applies.
- Customer-enabled logs, debugging records, replay data or evaluation datasets: for the retention period selected by the Customer; if none is selected, thirty (30) days, unless deleted earlier or a longer period is required for legal, security or enforcement reasons.
- Security and enforcement data: for as long as reasonably necessary to investigate, prevent, document, enforce, bring or defend claims relating to suspected or actual abuse, including unauthorized distillation, model extraction, scraping, fraud, non-payment, security incidents or unlawful activity, and may be retained until applicable limitation periods expire.
- Backups: processed according to backup cycles, generally overwritten or deleted within ninety (90) days, unless preserved for security, continuity or legal reasons.
The Customer may request deletion of certain Account Data or Customer API Data. We may refuse, delay or limit deletion where retention is required or permitted for legal compliance, billing, audit, security, anti-fraud, dispute resolution, evidence preservation, enforcement of rights, backups or legitimate business purposes.
12. Access, Correction and Regional Privacy Rights
Under the PDPO, individuals may have the right to request access to and correction of their personal data held by HaiToken. Requests may be sent to privacy@haitoken.ai.
Before responding, we may need to verify your identity and authority. Where permitted by law, we may charge a reasonable fee for a data-access request. Where permitted by the PDPO or other applicable law, we may refuse or limit a request, including where it involves other people's data, confidential information, legal privilege, security, anti-fraud, enforcement, evidence preservation or data controlled by a Customer.
If a request concerns Customer API Data controlled by a Customer, unless applicable law requires otherwise, we may refer the request to that Customer or handle it as instructed by the Customer.
Depending on your region and applicable law, you may also have additional rights, such as deletion, portability, restriction of processing, objection to processing, withdrawal of consent, complaint, or the right to opt out of direct marketing, sale, sharing, targeted advertising or certain profiling. Where such rights apply, you may exercise them through privacy@haitoken.ai. We do not sell Customer API Data, nor do we disclose Customer API Data for third-party advertising.
If the EU GDPR or UK GDPR applies to our processing of your personal data, you may also have the right to lodge a complaint with a supervisory authority with jurisdiction. We encourage you to contact us first so that we can address your concern promptly.
13. Security Measures
We maintain administrative, technical and organizational measures designed to protect personal data against unauthorized or accidental access, processing, deletion, loss or use. Where applicable, such measures may include:
- transport encryption using TLS 1.2 or higher;
- industry-standard encryption or equivalent safeguards for sensitive data at rest;
- access controls, least privilege, role-based permissions and administrative controls;
- API Key controls, credential management, rotation and revocation capabilities;
- logging, monitoring, anomaly detection, abuse detection and security alerts;
- network, infrastructure and application security controls;
- confidentiality obligations for employees and contractors;
- subprocessor due diligence and contractual controls;
- backup, continuity and incident-response processes; and
- optional controls where available, such as SSO, IP allowlisting, Provider allow/blocklisting, budgets, rate limits, PII detection or prompt-injection protection.
No method of transmission or storage can be completely secure. The Customer is responsible for protecting its own systems, applications, credentials, API Keys and end-user data.
14. Data Incidents
If HaiToken becomes aware of a confirmed security incident in its systems involving unauthorized access to or disclosure, loss, alteration or destruction of personal data, HaiToken will take the measures it considers appropriate in the circumstances to investigate, contain and remediate the incident.
Where required by applicable law, or where HaiToken reasonably believes the incident may materially adversely affect affected Customers or individuals, HaiToken will notify affected Customers without undue delay and provide reasonably available information to help Customers meet their own obligations. Notification is not an admission of fault or liability.
15. Cross-Border Transfers
HaiToken is located in Hong Kong, but the Services are designed to route requests to global Providers and infrastructure. Depending on the Provider, routing settings, region, cloud infrastructure, support arrangements and service providers selected by the Customer, personal data may be transferred to, stored in, accessed from or processed in locations outside Hong Kong.
The Customer authorizes HaiToken to make such transfers as necessary to provide the Services. The Customer is responsible for assessing whether the selected Providers, regions or routing meet the Customer's own legal, regulatory, contractual, confidentiality and data-residency obligations.
When HaiToken appoints service providers or subprocessors, it will use contractual or other reasonable measures to protect personal data, taking into account the nature of processing and applicable law.
Where the GDPR, UK GDPR or similar cross-border transfer rules apply, HaiToken will rely on an applicable lawful transfer mechanism, such as an adequacy decision, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, Customer-approved Provider routing selections, explicit consent where appropriate, or other mechanisms permitted by applicable law.
16. Direct Marketing and Communications
We may send administrative, security, billing and Service communications that are necessary or important for the Services. You cannot opt out of these communications while you maintain an account.
Where permitted by law or with necessary consent, we may send marketing or product communications. Under the PDPO, we will not use your personal data for direct marketing without taking the consent or opt-out steps required by law. You may opt out of marketing communications through the unsubscribe mechanism or by contacting us. Opting out of marketing does not affect administrative, security, billing or Service communications.
17. Audience, Eligibility and Minors
As described in our Service Agreement, the Services are offered to Customers located outside mainland China, including individual Customers, enterprise Customers, developers and organizations. Individual Customers must be at least eighteen (18) years of age. The Services are not offered to persons within mainland China. The Services are not directed to Children, and HaiToken does not knowingly solicit, collect or process personal data of a Child as an account holder or direct Customer.
If we become aware that a Child has created an account or provided personal data directly to HaiToken without appropriate authorization, we may delete the relevant account or data, restrict access, and take other measures required or permitted by law.
Unless the Customer has obtained all necessary authorizations, notices, consents, age thresholds, parental or guardian approvals, safeguards and legal bases under applicable law, upstream terms and the Customer's own policies, the Customer must not knowingly submit the personal data of minors or Children through the Services. The Customer is solely responsible for its own applications, end users and user-generated content, including any privacy obligations relating to minors or Children.
18. Third-Party Websites and Services
The Services may contain links, integrations or routing to third-party websites, documentation, APIs, models, tools or services. HaiToken does not control and is not responsible for the privacy, security or data practices of third parties. Customers should review the applicable third-party policies before use.
19. Changes to This Policy
We may update this Privacy Policy from time to time. We will indicate the update date and may provide additional notice of material changes by email, console notice, website announcement or other reasonable means. Continued use of the Services after the effective date of the updated policy means the updated policy applies to future processing.
20. Contact Us
To make a privacy request, access or correction request, complaint or inquiry, please contact:
LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司 Privacy: privacy@haitoken.ai Legal: legal@haitoken.ai
21. Additional Disclosures under GDPR, US State Laws and Legal Bases
The EU General Data Protection Regulation (GDPR), the UK GDPR and certain US state privacy laws require specific disclosures. This Section provides additional information about the categories of personal data we collect and how we use and disclose that information. You can learn about the personal data we collect and its sources in Section 4 ("Information We Collect"), how we use it in Section 6 ("How We Use Information"), how we retain it in Section 11 ("Retention and Deletion"), and your rights in Section 12 ("Access, Correction and Regional Privacy Rights").
Categories of personal data. As described above, the information we collect includes identifiers such as name, contact details, IP address and other device identifiers; commercial information such as transaction records; internet-activity information such as how you interact with the Services; communications information such as the contact details you provide when you email us; geolocation data such as the general area from which a device accesses the Services derived from information such as IP address, or precise location information you choose to provide; and account credentials.
Use of personal data and legal bases. We use this information to provide, analyze and maintain the Services, with a legal basis of performance of our contract with you; to improve and develop the Services and conduct research, with a legal basis of legitimate interests; to communicate with you, including sending Service and event information, with a legal basis of your consent; to prevent fraud, unlawful activity or misuse of the Services and to protect the security of our systems and the Services, with a legal basis of legitimate interests and legal obligations; and to comply with legal obligations and protect the rights, privacy, safety or property of users, HaiToken or third parties, with a legal basis of legitimate interests and legal obligations.
Disclosure of personal data. As described above, we may disclose personal data to vendors, service providers and affiliates to process on our instructions; to government authorities or other third parties for the legal reasons described above; to parties involved in a corporate transaction; and to other users and third parties with whom you interact or share information.
Sale and sharing. We market and promote our own products and services. We do not "sell" your personal data as defined by applicable laws and regulations, and we do not share Customer API Data for third-party advertising or cross-context behavioral advertising.