Home
Solutions
Website Page BuilderSEOLocalizationImage Library
PricingBlogHire Us
Start for Free

Privacy Policy

Effective: July 27, 2026 | Last updated: July 27, 2026

Tianfu Business Consulting Service (HK) Limited (“SudaWeb,” “we,” “us,” or “our”) respects the privacy of Customers and the confidentiality of their business data. This Policy explains how we process personal data about Customers and their members when operating app.sudaweb.ai and providing the Services.

This Policy is written for Customers that register for and use SudaWeb. For information a Customer collects from visitors, members, consumers, or other end users through its websites, the Customer generally acts as controller and SudaWeb acts as its processor or service provider. Each Customer must provide its own privacy notice to its End Users.

1. Scope and roles

This Policy applies when a Customer visits our website, creates an Account, manages a Project, purchases a Plan, contacts support, or otherwise uses the Services.

For Account registration, authentication, platform operations, billing, security, support, and legal compliance, Tianfu Business Consulting Service (HK) Limited acts as controller or business.

For Customer Business Data where the Customer determines why and how personal data is processed, the Customer acts as controller or business and SudaWeb acts as processor or service provider. We process that data only to provide the Services, follow documented Customer instructions, maintain security, and comply with law.

This Policy does not govern a Customer’s independent business activities and does not replace the privacy notice a Customer must provide to its End Users.

2. Personal data we process

Depending on the features used, we may process:

  • Account and contact data: name, email address, phone number, profile image, authentication data, language, and contact preferences;
  • Organization and member data: company name, job title, Project association, member roles, permissions, and invitations;
  • Project and Customer Content: Project names, website pages, text, images, files, domains, settings, and other material submitted by a Customer;
  • Customer Business Data: data a Customer collects or manages through forms, membership, orders, or other Project features;
  • Usage and device data: access time, features used, actions, browser, device type, network address, error data, and security logs;
  • Billing and transaction data: Plan, amount, currency, payment date, invoice details, transaction status, and a limited payment-method identifier. Payments are currently processed through Stripe, and full card details are generally processed directly by the payment provider;
  • Support and communications data: questions, complaints, refund requests, survey responses, emails, and support history;
  • AI feature data: instructions, context, attachments, selected Project material, and output generated through AI-assisted features;
  • Cookie data: login state, preferences, security identifiers, and choices relating to analytics or other optional cookies; and
  • Data from connected services: information supplied by login, domain, payment, or other third-party services that a Customer chooses to connect.

Do not submit government identifiers, biometric, health, precise location, financial account, or other highly sensitive data unless a specific Service expressly requires it and you have a lawful basis and appropriate safeguards.

3. Sources of personal data

We receive personal data:

  • directly from a Customer, administrator, or member;
  • automatically when the Services are used;
  • from third-party services a Customer chooses to connect;
  • when a Customer submits Customer Business Data and instructs us to process it; and
  • from lawful public sources or providers used for security and fraud prevention.

4. Purposes and legal bases

We process personal data as reasonably necessary to:

  • create and manage Accounts, Projects, members, and permissions;
  • perform our contract and provide website building, publishing, hosting, collaboration, and related functionality;
  • process subscriptions, renewals, refunds, invoices, and financial records;
  • verify identity and Account control and prevent fraud, abuse, and security threats;
  • provide support, troubleshoot issues, and send service and policy notices;
  • maintain, analyze, and improve reliability, usability, and performance;
  • generate AI output requested by a Customer;
  • comply with law, respond to lawful requests, and resolve disputes; and
  • send product news, events, or marketing where a Customer has consented or law otherwise permits.

Depending on the context and applicable law, our legal bases include performance of a contract, compliance with legal obligations, protection of vital interests, our legitimate interests in operating and securing the Services, and consent.

Where data is required for a core Service, refusing to provide it may prevent registration, payment, or use of that feature. A Customer may decline or withdraw consent for optional processing without losing unrelated core Services.

5. Customer Business Data

The Customer determines the purposes, scope, retention period, and use of Customer Business Data and is responsible for its lawfulness. We process Customer Business Data only to:

  • provide, maintain, and protect Services selected by the Customer;
  • perform actions based on Customer settings and instructions;
  • detect and address spam, fraud, abuse, and security incidents;
  • comply with applicable law and valid legal process; or
  • perform obligations in a separate written agreement with the Customer.

We do not sell Customer Business Data as a standalone data product, and we do not use it to target unrelated advertising to a Customer’s End Users.

End Users should direct access, correction, deletion, and similar requests to the relevant Customer. We will provide reasonable assistance to the Customer where required by law and supported by the Services.

6. AI-assisted features

When a Customer chooses an AI-assisted feature, we process instructions, selected Project material, attachments, context, and output to provide the feature, maintain security, and troubleshoot. Providers that help us deliver model or infrastructure functionality may process this data on our behalf.

Customers should not submit personal data, confidential information, or protected material they are not authorized to process and should review all output before use. We do not acquire ownership of Customer Content merely because a Customer uses an AI-assisted feature, unless expressly agreed otherwise.

7. Cookies and similar technologies

We may use:

  • Strictly necessary cookies for login, authentication, security, payment flows, and essential sessions;
  • Preference cookies to remember language, interface, and Project settings;
  • Analytics cookies to understand feature usage, find problems, and improve the Services; and
  • Advertising cookies only where actually enabled and lawfully consented to, to measure campaigns or provide relevant promotions.

A Customer can manage non-essential cookies through browser settings or a preference tool we make available. Blocking some cookies may affect functionality.

When a Customer enables cookies, analytics, or advertising tools on its own website, the Customer is responsible for giving End Users appropriate notice and obtaining consent where required.

8. Service providers, sharing, and corporate events

We may engage providers for cloud hosting and storage, content delivery, payment processing, email and messaging, customer support, identity and security, analytics, AI functionality, and professional advice. Providers may process only data reasonably needed for their services and are required to protect it under contractual and legal obligations.

We may share or transfer personal data:

  • at the Customer’s direction or with consent;
  • to complete a third-party connection the Customer has chosen;
  • in connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to continued protection; or
  • to comply with law, lawful government requests, or to protect the rights and safety of Customers, the public, and the Services.

We do not publish personal data except with authorization or where law permits or requires it.

9. International transfers

SudaWeb and its providers may process personal data in countries other than the country where a Customer is located. Those countries may have different data protection laws.

Where required, we use recognized safeguards such as contractual protections, transfer assessments, or other legally approved mechanisms. We also apply appropriate security measures and provide information needed for individuals to exercise applicable rights.

The Customer is independently responsible for lawful international transfers it initiates involving End User data.

10. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, taking into account the life of an Account, Customer settings, contract performance, dispute resolution, security, and legal requirements.

While an Account is active, we generally retain data needed to provide the Services. After closure or termination, we delete or de-identify data that is no longer needed within a reasonable period. Billing, transaction, audit, security, and dispute records may be retained for legally required periods.

Data in backups may remain until the applicable backup cycle completes. Access and use are restricted during that period.

11. Security and incidents

We use administrative, technical, and organizational measures appropriate to risk, including access controls, protected transmission, logging, backups, vulnerability management, and confidentiality requirements.

No online service can guarantee absolute security. If a personal data incident occurs, we will investigate, mitigate harm, and notify affected parties and authorities where required by law. Customers must manage permissions and credentials responsibly and report suspected issues promptly.

12. Privacy rights

Depending on applicable law, an individual may have rights to:

  • access and obtain a copy of personal data;
  • correct incomplete or inaccurate data;
  • request deletion;
  • restrict or object to processing;
  • withdraw consent;
  • receive portable data;
  • opt out of certain targeted advertising, sale, or sharing where those concepts apply;
  • appeal a denied request; and
  • complain to a competent data protection authority.

Customers and members can use available Account settings or email [email protected]. We may verify identity, authority, and Account ownership before acting. Requests involving Customer Business Data should normally be made through the relevant Customer administrator.

Withdrawing consent does not affect processing already lawfully completed. Closing an Account may make Projects, published sites, and related data unavailable, so retain needed copies before proceeding.

We will not unlawfully discriminate against an individual for exercising privacy rights.

13. Regional disclosures

13.1 EEA, United Kingdom, and Switzerland

Where applicable, our legal bases are described in Section 4. Individuals may contact a competent supervisory authority and may object to processing based on legitimate interests. International transfers use safeguards recognized under applicable law.

13.2 United States

Residents of certain states may have rights to know, access, correct, delete, obtain a copy, and opt out of specific sale, sharing, targeted advertising, or profiling activities. We do not sell Customer Business Data for money or use it for unrelated cross-context behavioral advertising. An authorized agent may submit a request where permitted, subject to verification.

13.3 Other regions

We honor rights required by the privacy law that applies to our processing. If local law provides greater protection than this Policy, the mandatory local requirements apply.

14. Customer obligations to End Users

When using SudaWeb to collect or process End User data, a Customer must:

  • publish a privacy notice that accurately reflects its processing and is visible before collection;
  • explain that SudaWeb and other providers may process data on the Customer’s behalf;
  • obtain consent required for cookies, marketing, sensitive data, or international transfers;
  • provide and respond to End User rights channels;
  • collect only data necessary for a defined business purpose; and
  • secure members, connected services, and exported data.

Templates, notices, or tools provided by SudaWeb do not replace the Customer’s own legal assessment.

15. Children

The Services are designed for adult Customers and business organizations, not for children. A Customer that collects children’s data through its website must obtain parental consent and comply with applicable child privacy laws.

If you believe a child has provided personal data to us without proper authorization, contact [email protected].

16. Changes to this Policy

We may update this Policy for changes in law, security, or the Services. If a change is material, we will provide notice through the website, Account, or registered email and obtain consent where required. The updated Policy applies from the date shown above.

17. Contact

Controller: Tianfu Business Consulting Service (HK) Limited

Service workspace: https://app.sudaweb.ai

Website: https://www.sudaweb.ai

Privacy and support email: [email protected]

We will respond after reasonable verification and within the period required by applicable law. Individuals may also complain to a data protection authority with jurisdiction over the matter.

Features

  • SEO
  • Multi-language
  • Image Library

Company

  • Contact Us
  • About Us
  • Security

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy

Services

  • Website Setup Service
  • Custom Development
Build professional websites with Sudaweb AI

© 2026 Sudaweb AI. All rights reserved.