HomeModelEnterpriseDocs
Contact Us

HaiRoute Privacy Policy

Last updated: 2026-07-02
Effective date: 2026-07-02
Data user: LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司
Version status: Publication version

Language

This Privacy Policy is prepared in English and Chinese. Both versions are intended to have legal effect. If there is any inconsistency, ambiguity or conflict between the English and Chinese versions, the English version shall prevail, unless HaiRoute expressly states otherwise in writing.


1. Introduction

This Privacy Policy explains how LDCY TECH HK LIMITED ("HaiRoute", "we", "us" or "our") collects, holds, processes, uses, discloses, transfers and protects personal data in connection with HaiRoute's websites, dashboards, APIs, unified model gateway, routing services, usage monitoring, enterprise administration, support and related services (the "Services").

HaiRoute is designed for customers located outside Mainland China who meet the eligibility requirements in our Terms of Service, including individual customers, business customers, developers and organisations. Individual customers must be at least eighteen (18) years old. The Services are not offered to, and must not be used by or for the benefit of, any individual or entity located in, established in, ordinarily resident in, or accessing the Services from Mainland China. The Services are not directed to children. In this Privacy Policy, "children" means any individual under the age of eighteen (18), or any older individual treated as a minor under the law applicable to that individual.

This Privacy Policy does not apply to the privacy practices of third-party model providers, infrastructure providers, integrations or services that are not controlled by HaiRoute. This Privacy Policy should be read together with HaiRoute's Terms of Service and, where applicable, the Data Processing Agreement ("DPA").


2. Who We Are and Our Role

For personal data collected and used for HaiRoute's own business purposes, such as account administration, website operation, billing administration, security, customer support, marketing communications and legal compliance, LDCY TECH HK LIMITED is the data user for purposes of the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO").

For Customer API Data submitted by or on behalf of a customer through the Services, the customer generally determines the purposes and means of processing. HaiRoute generally acts as a data processor or service provider processing such data on behalf of the customer, subject to the Terms of Service, this Privacy Policy and the DPA.

HaiRoute may also process limited information as an independent data user where necessary for security, fraud prevention, abuse detection, billing, legal claims, compliance, service integrity and enforcement of our rights.


3. Data Covered by this Policy

This Privacy Policy covers:

  1. Account Data: information about customer organisations, administrators, authorised users and contacts.
  2. Service Metadata: technical, usage, routing, billing, security and audit records generated by use of the Services.
  3. Customer API Data: prompts, inputs, conversation messages, files, images, audio, completions, outputs, training materials, fine-tuning materials, evaluation materials and other content submitted to, processed through, or returned through the APIs.
  4. Support Data: information provided in support tickets, emails, calls, chat messages, documentation requests and feedback.
  5. Website, Cookie and Analytics Data: information collected through our websites, dashboards, cookies, pixels and analytics tools.
  6. Security and Enforcement Data: logs, records, evidence and technical signals used to protect the Services, investigate misuse and enforce legal rights.

4. Information We Collect

We may collect the following categories of information:

  1. Account and organisation information: name, business email, company name, job title, role, department, organisation settings, billing contact, legal contact and support contact.
  2. Authentication and access information: login records, password or authentication method metadata, API key identifiers, token identifiers, permission settings, administrator actions, IP address, device identifiers and session information.
  3. Usage and billing metadata: timestamps, model identifiers, Provider identifiers, endpoints, token counts, request counts, latency, region, route, status codes, error codes, cost, Account Balance, Usage Credits, invoice records, subscription or plan information and budget events.
  4. Customer API Data: prompts, files, conversation messages, inputs, outputs, training or fine-tuning materials and related logs processed through the Services, subject to the seven-day rolling retention position and exceptions described below.
  5. Support and communications: messages, attachments, screenshots, logs or other information you provide when contacting us.
  6. Website and analytics data: browser type, operating system, referring pages, pages viewed, time spent, cookies, preferences and approximate location derived from IP address.
  7. Security and enforcement information: abuse signals, anomaly scores, rate-limit events, suspected scraping indicators, suspected model extraction or distillation indicators, content policy flags, provider blocks, investigation notes and legal hold records.

We may receive information directly from you, from your authorised users, from systems using your API keys, from Providers, from service providers, from security tools, from public sources, or from third parties involved in investigating misuse or enforcing legal rights.


5. Prompts, Completions and Customer API Data

HaiRoute's default operational configuration is to retain Customer API Data, including relevant prompt bodies, completion bodies, conversation records, files, outputs, training or fine-tuning materials submitted through the Services, and related logs, for a rolling period of up to seven (7) days after processing. This rolling retention is used to check whether there is unreasonable, abusive, unlawful or prohibited use; detect and investigate fraud, security incidents, scraping, unauthorised distillation, model extraction, misuse of Outputs or non-payment; resolve billing, routing, Provider and support issues; preserve and trace responsibility; and enforce the Terms of Service and Provider Terms.

After the seven-day rolling period, Customer API Data is automatically overwritten, deleted or de-identified in the ordinary course, unless an exception below applies. HaiRoute may separately retain Service Metadata necessary for billing, security, routing, performance, audit, fraud prevention, abuse detection, customer support, compliance and enforcement.

Exceptions may apply where:

  1. Customer enables logging, debugging, caching, replay, evaluation, dataset, fine-tuning, analytics or similar features;
  2. Customer or an authorised user includes prompts, outputs, files or logs in a support request or other communication with HaiRoute;
  3. HaiRoute reasonably believes preservation is necessary for security, abuse detection, fraud prevention, non-payment, chargebacks, legal compliance, Provider requests, service integrity, traceability of responsibility or enforcement of rights;
  4. HaiRoute reasonably suspects unauthorised distillation, model extraction, scraping, benchmark-to-replicate activity, misuse of Outputs, infringement or other violation of the Terms of Service or Provider Terms;
  5. retention is required by law, court order, arbitral tribunal, regulator, law enforcement authority or valid legal process; or
  6. temporary processing, queueing, retries, caching, backups, telemetry or operational logs are technically necessary to provide and secure the Services.

Where an exception applies, HaiRoute may generate, preserve, review, retain and disclose relevant Customer API Data, Service Metadata and related evidence for the period reasonably necessary for the relevant purpose, including investigation, enforcement, legal hold, dispute resolution, arbitration, litigation, regulatory response and applicable limitation periods, subject to the PDPO and other applicable law.

Except as described in this Privacy Policy, the Terms of Service, the DPA, Customer's configurations, Provider Terms or applicable law, HaiRoute does not sell, rent or knowingly disclose Customer API Data or Customer private data for unrelated commercial purposes. HaiRoute does not disclose Customer API Data for third-party advertising.


6. How We Use Information

We use information for the following purposes:

  1. to provide, operate, route, maintain, monitor and improve the Services;
  2. to authenticate users, manage accounts, API keys, permissions, organisations and security settings;
  3. to route Inputs to Providers and return Outputs;
  4. to calculate usage, deduct Account Balance or Usage Credits, issue invoices, collect fees and resolve billing disputes;
  5. to detect, prevent and respond to security incidents, fraud, abuse, scraping, unauthorised distillation, model extraction, misuse of Outputs, non-payment and violations of our Terms or Provider Terms;
  6. to preserve evidence, establish, exercise or defend legal rights, and conduct investigations, arbitration, litigation, regulatory responses or enforcement actions;
  7. to provide customer support, troubleshooting, technical notices and service communications;
  8. to analyse Service performance, reliability, latency, costs, routing quality and aggregate usage trends;
  9. to comply with legal, regulatory, accounting, tax, audit, sanctions, export control and corporate obligations, including eligibility and geographic-restriction checks; and
  10. to send product, security, administrative or marketing communications where permitted by law and user preferences.

Where the EU General Data Protection Regulation, the UK General Data Protection Regulation or similar laws apply, our legal bases may include performance of a contract, taking steps at your request before entering into a contract, legitimate interests in providing, securing, improving and enforcing the Services, compliance with legal obligations, consent where required, and the establishment, exercise or defence of legal claims.


7. Training and Product Improvement

HaiRoute does not use Customer API Data to train AI models or create model-improvement datasets by default.

For clarity, HaiRoute's seven-day rolling retention of Customer API Data for security, abuse detection, service integrity, billing, support, responsibility tracing and enforcement is not consent for HaiRoute to train AI models or create model-improvement datasets.

HaiRoute may use Customer API Data for training, fine-tuning, evaluation datasets, model-improvement datasets or similar purposes only if Customer has expressly opted in or entered into a separate written agreement. Any opt-in will describe the relevant scope, purpose, data category and available controls. Customer may withdraw opt-in consent prospectively through available controls or by written notice, unless a separate written agreement states otherwise.

HaiRoute may use aggregated or de-identified Service Metadata that does not identify Customer or any individual to analyse and improve the Services, including routing quality, latency, reliability, pricing, capacity planning and security.


8. Third-Party Providers

The Services route Customer API Data to third-party Providers selected by Customer, selected through Customer's configuration, or selected by HaiRoute's routing logic according to Customer's enabled settings. Providers may process, retain, log, train on, transfer or otherwise handle data according to their own terms and policies.

HaiRoute does not control all Provider practices. Customer is responsible for reviewing Provider Terms and privacy or data policies before using a model, and for selecting Providers appropriate for Customer's data sensitivity, industry, jurisdiction, confidentiality needs, regional requirements and compliance obligations. Where HaiRoute makes available a list of supported Providers and links to their data policies, that list is provided for convenience and may change from time to time.

Where Customer uses a Provider through HaiRoute, Customer authorises HaiRoute to disclose Customer API Data and related Service Metadata to that Provider as necessary to route requests, return Outputs, bill usage, troubleshoot issues, enforce Provider requirements and provide the Services.


9. Cookies and Analytics

We may use cookies, local storage, pixels, SDKs and similar technologies for authentication, session management, security, fraud prevention, preferences, analytics, product improvement and communications.

Some cookies are necessary for the Services to function. Other cookies or analytics technologies may be controlled through browser settings, dashboard settings or consent tools where available. Disabling certain cookies may affect availability or functionality.

We may use analytics tools to understand website and dashboard usage, diagnose issues, improve performance and measure communications. We do not use analytics tools to intentionally collect prompt or completion bodies unless Customer provides them through a relevant feature or support interaction.

Our current cookie deployment is described in the Cookie Policy. As of the effective date, HaiRoute does not deploy performance or analytics cookies, marketing or advertising cookies, or third-party analytics, advertising, bot-management or support-chat cookies on the Online Services unless and until the Cookie Policy is updated and any required consent mechanism is made available.


10. How We Share Information

We may disclose information to:

  1. Providers, to route requests, return Outputs, troubleshoot issues, comply with Provider Terms and enforce restrictions;
  2. service providers and subprocessors, including cloud hosting, databases, authentication, security, monitoring, analytics, customer support, email, billing administration, professional advisers and business operations vendors;
  3. administrators and authorised users within Customer's organisation, according to account permissions;
  4. regulators, law enforcement, courts, arbitral tribunals, government authorities, counterparties, Providers or advisers where we believe disclosure is required or appropriate for legal compliance, enforcement, dispute resolution, security, fraud prevention or protection of rights;
  5. parties to a merger, acquisition, financing, reorganisation, sale of assets, due diligence or similar corporate transaction; and
  6. other persons with Customer's instruction, consent or direction.

Except as described in this Privacy Policy (including a corporate transaction under paragraph 5 above), the Terms of Service, the DPA, Customer's configurations, Provider Terms or applicable law, we do not sell or rent Customer API Data, and we do not disclose Customer API Data for third-party advertising or unrelated commercial purposes.


11. Retention and Deletion

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, legal process, contract, audit, accounting, tax, security, dispute resolution or enforcement needs.

The current retention schedule is:

  1. Account Data and billing administration records: for the account term and up to seven (7) years after account closure where reasonably necessary for accounting, tax, audit, legal or dispute purposes.
  2. Service Metadata: up to twenty-four (24) months, unless a longer period is reasonably necessary for security, abuse prevention, billing disputes, legal claims or compliance.
  3. Customer API Data, including prompt bodies, completion bodies, conversation records, files, outputs, and training or fine-tuning materials submitted through the Services: rolling retention for up to seven (7) days after processing, then automatically overwritten, deleted or de-identified in the ordinary course, unless an exception in Section 5 applies.
  4. Customer-enabled logs, debugging records, replay data or evaluation datasets: for the retention period selected by Customer or, if no period is selected, thirty (30) days, unless earlier deleted or longer retention is required for legal, security or enforcement reasons.
  5. Security and Enforcement Data: for the period reasonably necessary to investigate, prevent, document, enforce against, bring or defend claims relating to suspected or actual misuse, including unauthorised distillation, model extraction, scraping, fraud, non-payment, security incidents or legal violations, and for applicable limitation periods.
  6. Backups: according to backup cycles, generally overwritten or deleted within ninety (90) days unless preserved for security, continuity or legal reasons.

Customer may request deletion of certain account data or Customer API Data. We may decline, delay or limit deletion where retention is required or permitted for legal compliance, billing, audits, security, fraud prevention, dispute resolution, evidence preservation, enforcement of rights, backups or legitimate business purposes.


12. Access, Correction and Regional Privacy Rights

Under the PDPO, individuals may have the right to request access to and correction of their personal data held by HaiRoute. Requests may be sent to privacy@hairoute.ai.

We may need to verify your identity and authority before responding. We may charge a reasonable fee for data access requests where permitted by law. We may refuse or limit a request where permitted by the PDPO or other applicable law, including where the request relates to another person's data, confidential information, legal privilege, security, fraud prevention, enforcement, evidence preservation or data controlled by a customer.

If a request relates to Customer API Data controlled by a customer, we may refer the request to that customer or act according to the customer's instructions, unless applicable law requires otherwise.

Depending on your location and applicable law, you may also have additional rights, such as rights to deletion, portability, restriction, objection, withdrawal of consent, appeal, or to opt out of direct marketing, sale, sharing, targeted advertising or certain profiling. Where such rights apply, you may exercise them by contacting privacy@hairoute.ai. We do not sell Customer API Data or disclose Customer API Data for third-party advertising.

If the EU GDPR or UK GDPR applies to our processing of your personal data, you may also have the right to lodge a complaint with a competent supervisory authority. We encourage you to contact us first so we can try to address your concern promptly.


13. Security Measures

We maintain administrative, technical and organisational measures designed to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. These measures may include, where applicable:

  1. encryption in transit using TLS 1.2 or higher;
  2. industry-standard encryption or equivalent safeguards for stored sensitive data;
  3. access controls, least privilege, role-based permissions and administrative controls;
  4. API key controls, credential management, rotation and revocation features;
  5. logging, monitoring, anomaly detection, abuse detection and security alerting;
  6. network, infrastructure and application security controls;
  7. employee and contractor confidentiality obligations;
  8. subprocessor due diligence and contractual controls;
  9. backup, continuity and incident response processes; and
  10. optional controls such as SSO, IP allowlists, provider allowlists or blocklists, budgets, rate limits, PII detection or prompt-injection protections where available.

No method of transmission or storage is completely secure. Customer is responsible for securing its own systems, applications, credentials, API keys and end-user data.


14. Data Incidents

If HaiRoute becomes aware of a confirmed security incident involving unauthorised access to or disclosure, loss, alteration or destruction of personal data in HaiRoute's systems, HaiRoute will take steps it considers appropriate in the circumstances to investigate, contain and remediate the incident.

Where required by applicable law or where HaiRoute reasonably believes the incident is likely to cause material adverse impact to affected customers or individuals, HaiRoute will notify affected customers without undue delay and provide information reasonably available to help customers meet their own obligations. Notification is not an admission of fault or liability.


15. Cross-Border Transfers

HaiRoute is based in Hong Kong, but the Services are designed to route requests to global Providers and infrastructure. Personal data may be transferred to, stored in, accessed from or processed in locations outside Hong Kong, depending on Customer's selected Providers, routing settings, regions, cloud infrastructure, support arrangements and service providers.

Customer authorises HaiRoute to make such transfers as necessary to provide the Services. Customer is responsible for assessing whether a selected Provider, region or route is appropriate for Customer's own legal, regulatory, contractual, confidentiality and data residency obligations.

Where HaiRoute appoints service providers or subprocessors, HaiRoute uses contractual or other reasonable measures designed to protect personal data, taking into account the nature of the processing and applicable law.

Where GDPR, UK GDPR or similar cross-border transfer rules apply, HaiRoute will rely on an applicable lawful transfer mechanism, such as adequacy decisions, standard contractual clauses, the UK international data transfer agreement or addendum, customer-approved Provider routing choices, explicit consent where appropriate, or another mechanism permitted by applicable law.


16. Direct Marketing and Communications

We may send administrative, security, billing and service communications that are necessary or important for the Services. These communications are not optional while you maintain an account.

We may send marketing or product communications where permitted by law or with required consent. In accordance with the PDPO, we will not use your personal data in direct marketing without taking any consent or opt-out steps required by law. You may opt out of marketing communications by using the unsubscribe mechanism or contacting us. Opting out of marketing does not affect administrative, security, billing or service communications.


17. Service Audience, Eligibility and Minors

As described in our Terms of Service, the Services are intended for customers located outside Mainland China, including individual customers, business customers, developers and organisations. Individual customers must be at least eighteen (18) years old. The Services are not offered to persons in Mainland China. The Services are not directed to children, and HaiRoute does not knowingly solicit, collect or process personal data from children as account holders or direct customers.

If we learn that a child has created an account or provided personal data directly to HaiRoute without appropriate authority, we may delete the relevant account or data, restrict access, and take other steps required or permitted by law.

Customer must not knowingly submit personal data of minors or children through the Services unless Customer has all required authority, notices, consents, age gates, parental or guardian approvals, safeguards and lawful bases under applicable law, Provider Terms and Customer's own policies. Customer is responsible for its own applications, end users and user-generated content, including any privacy obligations relating to minors or children.


18. Third-Party Sites and Services

The Services may contain links, integrations or routes to third-party websites, documentation, APIs, models, tools or services. HaiRoute does not control and is not responsible for the privacy, security or data practices of third parties. Customer should review applicable third-party policies before using them.


19. Changes to this Policy

We may update this Privacy Policy from time to time. We will indicate the updated date and may provide additional notice for material changes by email, dashboard notice, website posting or other reasonable means. Continued use of the Services after the effective date of an updated policy means the updated policy applies to future processing.


20. Contact Us

For privacy requests, access or correction requests, complaints or questions, please contact:

LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司
Privacy email: privacy@hairoute.ai
Legal email: legal@hairoute.ai

A world-leading large-model API gateway platform providing one-stop AI model integration and management.

Navigation

HaiRouteModelEnterpriseDocs

Legal

Terms of ServicePrivacy PolicyCookie Policy

Contact Us

official@hairoute.aiTelegram

A world-leading large-model API gateway platform providing one-stop AI model integration and management.

Navigation

HaiRouteModelEnterpriseDocs

Legal

Terms of ServicePrivacy PolicyCookie Policy

Contact Us

official@hairoute.aiTelegram

© 2026 HaiRoute. All rights reserved.

Terms of ServicePrivacy PolicyCookie Policy