Published: June 19, 2026 | Version: V1.0
QingdaoFu Property (Shenzhen) Co., Ltd. (hereinafter referred to as "we" or "the Company") attaches great importance to data security, strictly complies with the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, the Regulations on Network Data Security Management, and other laws and regulations, and in conjunction with the requirements of the Financial Information Service Data Classification and Grading Guide (Guo Xin Ban Tong Zi [2026] No. 2), has formulated this Data Security Statement to publicly commit to our data security protection responsibilities.
We commit to complying with the following laws, regulations, and standards:
We have established the following data security compliance system:
In accordance with the requirements of the Financial Information Service Data Classification and Grading Guide, we classify and grade business data following these principles:
Data involved in our business mainly includes the following categories:
| Data Category | Data Content | Typical Scenario |
|---|---|---|
| User Data | Client names, contact information, enterprise information | Consultation registration, business discussion |
| Business Data | Compliance consulting records, service contract information | Service delivery |
| Operational Data | Website access logs, system operation data | Website operation and maintenance |
In accordance with the Guide's four-level grading model (Core Data — Important Data — Sensitive General Data — Regular General Data), our current data grading is as follows:
| Data Grade | Our Involvement | Protection Measures |
|---|---|---|
| Core Data | Not involved | — |
| Important Data | Not involved (user scale has not reached the threshold of 10 million) | — |
| Sensitive General Data | Possibly involved (enterprise client business information, carbon emission data, etc.) | Encrypted storage + permission grading + desensitization |
| Regular General Data | Involved (public information, website logs, etc.) | Basic security protection |
| Security Area | Specific Measures |
|---|---|
| Transmission Security | Site-wide HTTPS encryption (SSL/TLS protocol) |
| Storage Security | Alibaba Cloud ECS enterprise-level security protection, data stored in mainland China |
| Access Control | Role-based access control (RBAC), principle of least privilege |
| Audit Logging | Key operations leave traces, supporting security incident traceability |
| Sensitive Data Protection | Sensitive general data encrypted for storage, desensitized when externally provided |
| Management Area | Specific Measures |
|---|---|
| Organizational Assurance | Designated data security responsible person, established data security management system |
| Personnel Management | Security training and confidentiality constraints for personnel accessing sensitive data |
| Vendor Management | Data processing agreements signed with data processing service providers, clarifying security responsibilities |
| Emergency Management | Data security incident emergency plan established, regular drills conducted |
| Compliance Self-Inspection | Data security compliance self-inspection conducted at least once annually |
| Phase | Security Requirements |
|---|---|
| Data Collection | Lawful, legitimate, necessary, with explicit collection purpose |
| Data Storage | Classified and graded storage, sensitive data encrypted, stored in China |
| Data Usage | Used within authorized scope, prohibited from unauthorized processing or analysis |
| Data Transmission | Encrypted transmission, cross-border transmission subject to security assessment per law |
| Data Deletion | Timely deletion or anonymization after retention period expires |
If personal information or important data needs to be provided overseas, we will apply to the national cyberspace administration for a data export security assessment in accordance with the law, and will not conduct cross-border transfers before passing the security assessment.
QingdaoFu Academy learning services are hosted and operated by the Coze platform, with the following security measures:
We have established a data security incident emergency plan, clarifying incident grading standards, response procedures, and handling measures.
After a data security incident occurs, we will report to the competent authorities in a timely manner in accordance with the requirements of the Regulations on Network Data Security Management, and notify affected users through website announcements, emails, and other means, informing them of the possible impact and remedial measures taken.
We may revise this statement from time to time. The revised statement will be published on this website and shall take effect from the date of publication. Significant changes will be notified to users through reasonable means such as website announcements.
If you have any questions about our data security measures, please contact us through the following:
This statement is formulated and interpreted by QingdaoFu Property (Shenzhen) Co., Ltd.