tencent cloud

DocumentationTencent Cloud DataBuddyAgreementsTencent Cloud DataBuddy Privacy Policy

Tencent Cloud DataBuddy Privacy Policy

Download
Focus Mode
Font Size
Last updated: 2026-09-15 09:47:09
AI-Translated
Welcome to Tencent Cloud DataBuddy!

This Privacy Policy explains the when, how, and why of the processing of personal information in connection with Tencent Cloud DataBuddy ("DataBuddy" or the "Service"), and sets out the choices and rights available in relation to that information. DataBuddy is an Agent-Native, fully managed Data + AI intelligent data platform offered by Tencent Cloud.

For the purposes of data protection laws, the data controller of the personal information described in this Privacy Policy is Tencent Cloud International Pte. Ltd. ("TCI"), a Singapore-registered company located at 10 Anson Road, #21-07, International Plaza, Singapore 079903 ("we", "us", "our"). TCI is the Tencent group entity that operates the Tencent Cloud International platform.

DataBuddy is provided to enterprise customers ("Customer(s)") for use by their staff such as their administrators and authorised end users ("User", "you" or "your"). This Privacy Policy applies to the personal information for which we act as the controller – that is, information we collect and determine the purposes and means of processing in order to operate the Service, manage accounts, facilitate billing process, and maintain, secure and improve the Service.
Note:
Important - where we act as a processor. DataBuddy functions as an AI-powered data platform and supports the "bring-your-own-key" ("BYOK") model. The Customer is the data controller and we act as the data processor on behalf of the Customer, in the following circumstances:
the content that the Customer and its Users submit to, and generate through, the Service – including prompts, queries, conversation history, uploaded files and documents used for designated workloads, and AI-generated outputs ("Customer Content"); and
to the extent a third-party LLM is incorporated into the Service at the Customer's selection and authorisation, the Customer's configuration settings ("Customer Configuration Information").
Our processing of Customer Content and Customer Configuration Information is governed by the Data Processing and Security Agreement (DPSA) entered into with the Customer, and not by this Privacy Policy. Please refer to that Customer's own privacy policy for information on how personal information contained in such Customer Content and Customer Configuration Information is processed.

If you do not agree to the processing of personal information as described in this Privacy Policy, please do not provide your information when requested and stop using the Service. By using the Service you acknowledge the processing described here and, to the extent required by the applicable law in your jurisdiction, you consent to the processing of your personal information as described in this Privacy Policy.

This Privacy Policy applies specifically to Tencent Cloud DataBuddy. Because DataBuddy is an agentic AI product that does not fall within any standard Tencent Cloud product category, this Privacy Policy is a standalone, product-specific notice and operates in addition to (and, in respect of DataBuddy, prevails over) the TCI umbrella privacy policy to the extent of any conflict.

Relationship to the umbrella structure: TCI adopts a hybrid model in which an umbrella privacy policy (TCI as controller) and an umbrella DPSA (TCI as processor) cover products generally, supplemented by category-specific documents. As DataBuddy cannot be assigned to a product category, this Privacy Policy – together with the DataBuddy DPSA – constitutes the DataBuddy-specific privacy documents.

Contents

1. What is DataBuddy?
2. Children
3. How We Process Your Personal Information
4. How We Store and Share Your Personal Information
5. The Security of Your Personal Information
6. Data Retention
7. Your Rights
8. Contact
9. Third-Party Websites, LLMs, Connectors, Data Sources and Code Repositories
10. Changes
11. Language
12. Jurisdictional Addendum

1. What is DataBuddy?

Tencent Cloud DataBuddy is an Agent-Native, fully managed Data + AI intelligent data platform. It converges data computing with AI-Agent capabilities and, via a unified metadata and semantic layer, delivers end-to-end enterprise data lifecycle capabilities – from data ingestion, data engineering, data science and data analytics to data governance.
DataBuddy shifts the big-data platform paradigm from "humans operating tools" to "AI performs the work, humans stay in the loop". Through natural-language interaction, users can complete complex workloads such as data ingestion, ETL pipeline construction, metric definition, anomaly root-cause analysis and interactive dashboard creation – significantly lowering the barrier to entry and the operational cost of running an enterprise data platform.
Warning:
When providing input to DataBuddy, please do not disclose personal information (whether your own or that of others) that is not necessary for the task. Any personal information included in prompts may be transmitted to and processed by the third-party LLM providers, MCP connectors, data sources or code repositories selected by the Customer, and may be reproduced in outputs.


2. Children

The Service is intended for enterprise use and must not be used by children. By children, we mean individuals under the age of 18 (or, in a region where the minimum age for processing personal information differs, such different age). We do not seek nor knowingly collect personal information from children. If you believe we hold personal information of anyone under the applicable minimum age, please contact us as set out in Section 8 (Contact).

3. How We Process Your Personal Information

This section describes the categories of User personal information we process as the controller, why we process it, and the legal basis on which we rely to the extent required by the data protection laws in your jurisdiction. Where the laws in your jurisdiction do not recognise the legal basis identified in the table below and consent is the only legal basis available, we will either seek consent from you directly during the sign-up process or rely on the consent obtained by our Customer on our behalf (to the extent your personal information is provided by the Customer to us).
Personal Information
Use
Legal Basis (where applicable)
Login and account information – including your Tencent Cloud account identifiers; login channels and authentication attributes; workspace membership and account lifecycle information; and other contact details such as your email, mobile number, employee ID, department, job title.
To create, authenticate and manage accounts and sub-accounts for the Service, and to operate and provide the Service.
Necessary to perform our contract with you to provide the Service.
We have a legitimate interest in securely administering and operating the Service.
We, and our Customer, have a legitimate interest in preventing unauthorised access, misconducts or abuse of the Service.
TCI defined configuration information – feature entitlement and programme configuration; and for Kimi LLM only, conversation logs; agent-generated long-term memory; RAG context; tool-call records; embeddings; workspace content artefacts produced through AI interaction.
To manage accounts and to operate and provide the Service.
Necessary to perform our contract with you to provide the Service.
We have a legitimate interest in securely administering and operating the Service.
Security and abuse prevention data – suspicious activity signals; anomaly scores; rate-limit and quota counters; and incident investigation records
To manage accounts, to operate and provide the Service and to identify security issues or abuse activities and safeguard the security of our systems.
Necessary to perform our contract with you to provide the Service.
To perform the legal obligations imposed on us (such as cyber/data security obligations).
We have a legitimate interest in maintaining, securing and improving the Service.
We, and our Customer, have a legitimate interest in protecting the data assets of our Customers.
Billing and consumption information – billing account identifier; order details records; in-product consumption aggregates; and subscription status reference.
To manage billing accounts, subscriptions and service plans, and to track usage.
Please note that payment information (such as payment card details, invoices, billing address, etc) will not be processed by the DataBuddy product team, but by TCI's billing and payment systems centrally. Please refer to TCI's umbrella privacy policy for details about how payment information is processed.
Necessary to perform our contract with you to provide the Service.
To perform the legal obligations imposed on us (such as accounting, tax and audit obligations).
We have a legitimate interest in ensuring sound operation of our business through accurate billing and service management.
Diagnostic and usage data – device information (device model and brand, operating system and version, browser type and version, screen resolution, system language and time zone); network information (IP address, network type, carrier if applicable, approximate location); and log information (access time, operation type, request records, error logs, crash records, and performance metrics such as API response time and error rate).
To ensure compatibility, to provide security protection and access control, to conduct security audits, to monitor the performance and quality of the Service, to detect and identify errors and bugs, to troubleshoot, and to improve and optimise the Service.
Necessary to perform our contract with you to provide the Service.
To perform the legal obligations imposed on us (such as cyber/data security obligations).
We have a legitimate interest in maintaining, securing and improving the Service.
We, and our Customer, have a legitimate interest in protecting the data assets of our Customers.
Compliance records - consent and withdrawal records; data subject request records, sub-processor authorisation records; retention and deletion evidence; government or regulator requests; and any other personal information required to be retained or disclosed pursuant to applicable laws, regulations, court orders or government requests.
To comply with applicable legal obligations, respond to regulatory requests, and fulfil data subject rights.
To fulfil our legal obligations.
Any data categories stated above, as the case may be.
To establish, exercise or defend our legal rights, including against legal claims and liabilities that involve us or other Tencent affiliates.
We have a legitimate interest in protecting ourselves against legal claims.

Cookies

DataBuddy is made available through the Tencent Cloud International platform. The use of cookies and similar technologies on that platform is governed by TCI's umbrella privacy policy and the TCI Cookies Policy published on the same site, which apply to your use of DataBuddy. Please refer to those documents for details of the cookies used and the choices available to you.

4. How We Store and Share Your Personal Information

Where we store your information: The personal information described in Section 3 is stored on Tencent Cloud infrastructure within Singapore (for account-layer and console-layer information) or one of the launch regions of the Service at your choice: Singapore, Hong Kong, Thailand and Indonesia (for workspace-layer information).
Global support and remote access: We have global support, engineering and other teams which support the Service, including personnel located in the mainland of the People's Republic of China ("PRC", and for the purposes of this Privacy Policy, excluding Hong Kong and Macau Special Administrative Regions and Taiwan region). Our first-line troubleshooting is handled by TCI's customer support team in Singapore and/or the launch regions (which includes personnel based within or outside your home jurisdiction); the PRC-based R&D team is engaged only for complex technical issues. Where remote access by the PRC R&D team is necessary, only the limited data required for troubleshooting is accessed. Personal information is stored in Singapore, Hong Kong, Thailand and Indonesia, and is not transferred back to the PRC, save for limited remote access strictly necessary for troubleshooting.
Safeguards: Where personal information is transferred across borders or remotely accessed from another jurisdiction, we implement safeguards required by applicable law, including reliance on TCI's intra-group data transfer agreement incorporating the applicable standard contractual clauses (SCCs), transfer impact assessments, data processing agreements with third-party processors, and other contractual safeguards.
Processing within the Tencent group: Payment and billing information is processed through the TCI payment system and TCI billing system. These are systems operated within the Tencent group to support the Tencent Cloud International platform. Processing by these systems is internal Tencent group processing and does not constitute disclosure of your personal information to an external service provider. All such Tencent group systems may only use your personal information in accordance with this Privacy Policy.
We share personal information with third parties in the following situations:
Third parties that provide services in support of the Service. We will transfer the TCI-defined configuration information in connection with Kimi LLM, the in-product model, to Moonshot AI, which processes such information as a data processor on our behalf. Moonshot AI is bound by confidentiality and data protection obligations to process your personal information only for the purposes set out in this Privacy Policy, and does not use any of your personal information for model training.
Regulators, judicial authorities and law enforcement. There are circumstances in which we may be legally required to disclose personal information, such as to comply with legal obligations or processes.
Safety, security and compliance. We may disclose personal information to (a) enforce our terms; (b) detect, prevent or address security, fraud or technical issues; or (c) protect the rights, property or safety of us, our users, a third party or the public, as required or permitted by law.
Professional advisors. We may disclose personal information to auditors, law firms or accounting firms.
Corporate transactions. We may disclose personal information if we sell, transfer, merge, consolidate or reorganise any part of our business.
Third party LLM providers, MCP connectors, data sources and code repositories: Because DataBuddy supports the BYOK model, the LLM providers (except for Moonshot AI which provides the in-product Kimi LLM), MCP connectors, data sources and code repositories used with the Service are selected and authorised by the Customer and its Users. When you choose to use them, Customer Content and Customer Configuration Information may be shared with those third parties based on your own selection and authorisation. The processing by other third parties is governed by their own privacy policies. See Section 9.

5. The Security of Your Personal Information

We adopt technical and organisational measures to protect personal information, including:
transfer security: all data is transmitted over HTTPS/TLS encrypted channels;
storage security: data is stored on Tencent Cloud infrastructure within the launch-region data centres, using a multi-tenant network isolation architecture in which each enterprise's AI assistant runs on an isolated cloud server instance;
access control: firewalls, port stealth, access control measures, and security-group (inbound/outbound network rule) configuration;
AI safeguards: a four-layer AI defence-in-depth approach comprising security auditing, permission control, network isolation and sensitive-content detection; and AIGC labelling (explicit and implicit labels) added to generated content;
organisational measures: dedicated information-security management systems, processes and teams; strict limitation of personnel access; confidentiality obligations and staff review; regular security education and training; and early-warning mechanisms and incident response plans, including breach reporting and notification obligations under applicable law; and
access rights management: identity authentication via the Tencent CAM; Customer administrators manage User permissions and operation traceability (management operation logs) via the admin console; data access rights controlled by the Customer.
Unfortunately, transmission of information via the internet is not completely secure. Although we implement and maintain reasonable measures to protect your personal information, we cannot guarantee the security of information transmitted via the internet; any transmission is at your own risk.

6. Data Retention

We do not keep personal information for longer than necessary to fulfil the purposes described above, unless we are required or permitted to retain it under applicable law. The periods below are maximum retention periods (i.e. we retain the relevant information for no longer than the stated period); we may delete or anonymise it sooner where it is no longer needed. The retention periods below apply to the personal information for which we act as controller. Retention of Customer Content and Customer Configuration Information is addressed in the DPSA.
Personal Information
Retention Period
Login and account information
Retained for as long as the account is maintained. Upon account deletion, deleted or anonymised within 1 month after the account/service is terminated, or immediately upon the Customer's request, whichever comes earlier.
TCI-defined configuration information
Retained for up to 1 month after the account/service is terminated, or until the Customer's request for deletion, whichever comes earlier.
Security and abuse prevention data
Retained for up to 1 month after the account/service is terminated, or until the Customer's request for deletion, whichever comes earlier.
Billing and consumption information
Retained for up to 1 month after the account/service is terminated, or until the Customer's request for deletion, whichever comes earlier.
Diagnostic and usage data
Retained for up to 1 month after the account/service is terminated, or until the Customer's request for deletion, whichever comes earlier.
Compliance records
Retained for no longer than is necessary to fulfil the applicable legal obligations.

7. Your Rights

Depending on where you are located, you may have some or all of the following rights in respect of your personal information. Some rights only apply in certain circumstances. You can exercise certain rights directly through your account or the user console; otherwise you can exercise them (including erasure and relevant opt-outs) by contacting us using the details in Section 8 (Contact). Enterprise administrators may also perform User management and configuration management via the admin console, and authorised end users may access, copy, correct, delete, deregister or withdraw consent via the user console.
Access: You have the right to access the personal information we hold about you, how we use it, and who we share it with.
Portability: You may have the right to receive a copy of certain personal information we process about you in a structured, commonly-used and machine-readable format.
Correction: You have the right to correct inaccurate personal information we hold about you.
Erasure: You may be able to delete your account or remove certain personal information via the user console or by requesting erasure from us. The Service also provides an option to delete the User's account within the application.
Restriction: You may have the right to require that we stop processing your personal information (other than for storage in certain circumstances).
Objection: You may have the right to object to our processing in certain situations.
Consent withdrawal: To the extent provided by applicable law, you may withdraw consent you previously provided by contacting us. Where consent is required and you do not consent or withdraw it, we may be unable to deliver the expected Service.
You also have the right to lodge a complaint with us, and with the relevant data protection authority in the jurisdiction where you live or work.

8. Contact

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us in the first instance at:
Email: cloudlegalnotices@tencent.com
We will endeavour to deal with your request as soon as possible. This is without prejudice to any right you may have to lodge a complaint with a data protection authority in the jurisdiction where you live or work.

9. Third-Party Websites, LLMs, Connectors, Data Sources and Code Repositories

The Service allows the Customer and its Users to select and integrate third-party LLM providers (via BYOK), MCP connectors, data sources and code repositories. These integrations are enabled at the Customer's and Users' own selection and authorisation.
LLM providers: Customer Content and Customer Configuration Information is transmitted via DataBuddy to the Customer-selected model provider for processing and is handled independently by that provider under its own privacy policy and terms. Before adding an LLM provider, Users are informed (via an in-product pop-up) that doing so will share data with that third party.
Connectors, data sources, code repositories and other tools: Users may install first-party and third-party connectors, data sources, code repositories and other tools, which are configured by Users and used at the User's own risk; before linking, Users are informed of the personal information the connection will access and the third party's privacy practices, and of potential sensitive-data disclosure risks.
We are not responsible for the privacy or security practices of third parties other than our sub-processors. Our inclusion of links or integration options does not imply endorsement. Please review the applicable third-party policies and terms. To revoke an integration, Users can remove the provider or revoke DataBuddy's authorisation in the relevant third-party application, or contact us at cloudlegalnotices@tencent.com to submit a withdrawal request.

10. Changes

If we make changes to this Privacy Policy, we will post the updated Privacy Policy here and notify you in accordance with relevant legal requirements, including through an in-product pop-up notice.

11. Language

Except as otherwise prescribed by law, in the event of any discrepancy or inconsistency between the English version and a local-language version of this Privacy Policy, the English version shall prevail.

12. Jurisdictional Addendum

The Service is initially made available in Singapore, Hong Kong, Thailand and Indonesia. The following supplements apply to the extent relevant to those launch jurisdictions.

Singapore

TCI is established in Singapore. We process personal information in accordance with the Personal Data Protection Act 2012 (SG PDPA). You may contact us at cloudlegalnotices@tencent.com regarding access, correction and withdrawal of consent, and you may lodge a complaint with the Personal Data Protection Commission (PDPC).

Hong Kong

We process personal data in accordance with the Personal Data (Privacy) Ordinance (PDPO). You may exercise your data access and correction rights by contacting us at cloudlegalnotices@tencent.com, and may lodge a complaint with the Office of the Privacy Commissioner for Personal Data (PCPD).

Thailand

We process personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA). Please include the word "Thailand" in the subject line of any request sent to cloudlegalnotices@tencent.com. You may lodge a complaint with the Personal Data Protection Committee.

Indonesia

We process personal data in accordance with Law No. 27 of 2022 on Personal Data Protection (PDP Law). You may exercise your rights, including access, correction, and deletion, by contacting us at cloudlegalnotices@tencent.com.

Malaysia

We process personal data in accordance with the Personal Data Protection Act 2010 (as amended in 2024) (MY PDPA). You may exercise your rights, including access, correction, and deletion, by contacting us at cloudlegalnotices@tencent.com, and you may lodge a complaint with the Personal Data Protection Commissioner (PPDP).

Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback