Back to TOPPP

Last updated:

Privacy Policy

This policy explains how the operator of TOPPP ("we", "us") collects, uses, shares and protects information when you use TOPPP, and how you can exercise your rights. We collect only what running the Service requires, we do not sell personal information, and we do not use your business data to train models.

1. Scope, and the two roles we act in

This policy covers toppp.ai and topppai.cn and the services offered through them.

TOPPP is a business service, so we handle information in two different roles. Work out which one applies to you first — it determines who you should direct a request to.

  • For the personal information of site visitors and account holders — what you generate when you register and use the platform — we are the personal information handler, or "controller" in GDPR terms. This policy applies to you directly.
  • For the business data you upload, and for conversations between an agent and your End Users, you are the controller and we process on your instructions as a processor. End Users should bring rights requests to you; we will help you answer them.

2. What we collect

These are all the categories we actually collect.

  • Registration and sign-in: your email address, the email verification code, and what you type into the image captcha.
  • When you sign in with Google: your name, email address and profile picture, received from Google.
  • Account and organisation: the name of the organisation or workspace you belong to, and your role in it.
  • What you configure: an agent's sales role, knowledge and method, business rules, sales material, and callable tool configuration.
  • Data the Service produces: conversations between an agent and your End Users, sales SOP progress, the customer profile an agent builds, and evaluation test cases and results.
  • Logs: IP address, browser and device type, access time, records of pages and actions, and error information.
  • Push messaging: the connection and installation identifiers needed to hold a real-time connection open.
  • We use no third-party analytics or advertising tooling. The site carries no Google Analytics, no Baidu Tongji, no Umeng and no other analytics SDK, and no third-party ad or tracking pixels.
  • We do not collect identity document numbers, bank account details, biometric data or health data through the site. The site also has no file upload.

3. How we use it

We use the information above only for the purposes listed here.

  • to create and maintain your account, verify who you are, and keep you signed in;
  • to run the core of the Service: running agents, engaging and advancing customer conversations, running evaluations, and supporting human takeover;
  • to send you notices about your account, your enquiries, or the state of the Service;
  • to keep the Service secure: spotting unusual sign-ins, preventing abuse and attacks, and diagnosing faults;
  • to measure how the Service is used, in aggregate form that cannot be traced to an individual, so that we can improve it;
  • to meet legal obligations and to cooperate with regulatory or judicial process;
  • to send you product updates or event invitations, where you have separately opted in. You can withdraw that consent at any time; withdrawal does not affect processing carried out before it.

4. AI processing and model training

When an agent runs, the knowledge, business rules and sales material you configured, together with the current conversation context, are sent to a model for inference so that it can generate a reply and decide the next step. This processing is what providing the Service consists of.

We do not use Customer Data to train or improve any machine learning model, and we do not pass it to model providers for their training.

We do not use your Customer Data to serve any other customer. The evaluation workbench runs on your own test cases and conversation records; nothing is shared across customers.

If this ever changes, we will tell you prominently before the change takes effect, and obtain your consent again where the law requires it.

5. Sharing and disclosure

We do not sell personal information, and we do not share it for anyone else's independent marketing.

We share information, and only as much of it as is necessary, in the following situations.

  • Service providers acting on our instructions: cloud compute and storage, content delivery, push messaging and email delivery. They may process information only as we instruct and only as far as providing the service requires, and they are bound by confidentiality and security obligations.
  • Google: if you choose to sign in with a Google account, Google handles that step and Google's privacy policy applies to it. You can register with an email verification code instead, which involves no Google processing.
  • Legal requirements: where disclosure is required by law, by a regulator, or by judicial process.
  • Business changes: in a merger, acquisition or transfer of assets, information may transfer as part of those assets. We will tell you before that happens and require the recipient to maintain protection no weaker than this policy.
  • If you need the list of service providers involved in your account, ask us for it.

6. Cookies and local storage

We use only the cookies and browser local storage that keeping the Service running requires. Nothing here is used for advertising or cross-site tracking.

Here is what we set. You can clear it through your browser, but you will then need to sign in again and some interface preferences will reset.

  • Session cookies: uid, ptoken, token, mid, cate, atype. These identify your session so you do not have to sign in again on every action.
  • Local storage: your interface language, light or dark theme, and the state of a flow you have not yet submitted. This stays in your browser.
  • We set no advertising cookies, no third-party tracking cookies and no cross-site identifiers.

7. Where data is stored, and cross-border transfer

topppai.cn serves users in mainland China, and its data is stored inside mainland China.

toppp.ai serves users outside mainland China, and its data is stored outside mainland China.

The two deployments are independent. Data is processed and stored in the region matching the site you registered on, so no cross-border transfer of personal information takes place. If that arrangement changes, we will tell you in advance and follow the procedure the Personal Information Protection Law requires.

8. How long we keep it

We keep information for the shortest period that achieves the purpose it was collected for, and delete or anonymise it after that.

  • Account information: kept while the account exists. After you close the account we delete or anonymise it, except where the law requires us to keep it.
  • Business and conversation data: kept while you use the Service. When you delete content we remove it from production; copies on backup media are cleared on the backup rotation cycle.
  • Logs and security records: China's Cybersecurity Law requires network logs to be kept for at least six months, and we keep them for that period and for as long as security requires.

9. Security

We apply management and technical measures proportionate to the risk, including encryption in transit (HTTPS and WSS), role-based access control on a least-privilege basis, audit logging, and workspace isolation between lines of business.

No method of transmission or storage over a network is completely secure.

  • If a personal information security incident occurs that could affect you, we will tell you what was affected, what we have done about it, and what you can do, as the law requires; where we are obliged to report it to a regulator, we will do that as well.

10. Your rights

Under China's Personal Information Protection Law you may access, copy, correct, supplement and delete your personal information, ask us to explain how we process it, withdraw consent you have given, and close your account.

If you are in the European Economic Area, the United Kingdom, or another place where the GDPR applies, you also have the right to a portable copy of your data, to restrict processing, to object to processing, and to complain to your local supervisory authority.

  • How to exercise them: send us a request.
  • We will verify who you are and reply within fifteen working days of receiving your request; if the request is complex, we will tell you why we need longer and when to expect an answer.
  • If we decline a request, we will explain why and tell you what recourse you have.
  • If you are an End User of one of our customers, please make the request to that customer. As their processor, we will assist on their instructions.

11. Minors

The Service is for business users and is not directed at minors. We do not knowingly collect personal information from children under fourteen.

If you believe we may have done so, contact us and we will verify and delete it promptly.

12. Changes to this policy

We may update this policy. The updated version is published on this page with the date it was updated.

Where the purpose of processing, the way we process, or the categories of personal information change materially, we will tell you prominently by in-product message, email or similar; where the law requires it, we will ask for your consent again.

13. Contact us

This policy is published by TOPPP.

  • Operating entity: HIII PTE. LTD.