BeeMatch.AI
Back to website

BeeMatch ZhiFengXunYuan · Data Processing Agreement

BeeMatch 智蜂尋源 · 數據處理協議

Last updated: September 5, 2026

最後更新日期:2026 年 9 月 5 日

1. Parties to the Agreement

1. 協議當事方

This Data Processing Agreement (the "DPA") is entered into by and between the following parties:

本數據處理協議(以下簡稱「本 DPA」)由以下雙方訂立:

  • Data Controller: BeeMatch AI Technology Limited, a company incorporated under the laws of the Hong Kong Special Administrative Region, with its registered address in the Hong Kong Special Administrative Region ("BeeMatch" or the "Controller"); and

數據控制者:BeeMatch AI Technology Limited,一家依據香港特別行政區法律註冊成立的公司,註冊地址爲香港特別行政區(以下簡稱「BeeMatch」或「控制者」);與

  • Data Processor: Creator (Influencer), the individual or entity that registers and uses the ZhiFengXunYuan Platform to undertake Campaign collaborations and process Brand-related data ("Creator" or "Processor").

數據處理者:創作者(達人),即註冊並使用智蜂尋源平臺接受 Campaign 合作並處理品牌方相關數據的個人或實體(以下簡稱「創作者」或「處理者」)。

The Controller and the Processor are collectively referred to as the "Parties" and individually as a "Party". This DPA forms an integral part of the Creator Service Agreement between the Parties and governs the Processor's processing of Brand personal data and other applicable data in the course of providing Campaign services.

控制者與處理者合稱「雙方」,單稱「一方」。本 DPA 構成雙方之間《創作者服務協議》的組成部分,規範處理者在提供 Campaign 服務過程中處理品牌方個人數據及其他適用數據的行爲。

2. Definitions

2. 定義

Unless the context otherwise requires, the following terms used in this DPA have the meanings set out below:

除上下文另有所指外,本 DPA 中下列術語具有如下含義:

  • "Personal Data" means any information relating to an identified or identifiable natural person, with the meaning consistent with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) and applicable data protection laws.

「個人數據」 指與已識別或可識別的自然人相關的任何信息,其含義與香港《個人資料(私隱)條例》(第 486 章)及適用數據保護法律中的定義一致。

  • "Processing" means any operation or set of operations performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, transmission, deletion, or destruction.

「處理」 指對個人數據進行的任何操作或一系列操作,包括收集、記錄、組織、存儲、改編、檢索、使用、披露、傳輸、刪除或銷燬。

  • "Data Subject" means the natural person to whom personal data relates.

「數據主體」 指個人數據所涉及的自然人。

  • "Brand Data" means Brand-related information provided by the Controller to the Processor through the Platform in connection with a Campaign, including but not limited to brand name, product information, Brief content, promotional materials, and Brand contact information.

「品牌方數據」 指控制者通過平臺向處理者提供的、與 Campaign 相關的品牌方信息,包括但不限於品牌名稱、產品信息、Brief 內容、推廣素材及品牌方聯繫人信息。

  • "Sub-processor" means any third party engaged by the Processor to process personal data on behalf of the Processor.

「分處理者」 指處理者委託的、代表處理者處理個人數據的任何第三方。

  • "Data Security Incident" means a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

「數據安全事件」 指導致個人數據意外或非法銷燬、丟失、更改、未經授權披露或訪問的安全事件。

3. Scope and Purpose

3. 適用範圍與目的

This DPA applies to all activities in which the Processor processes Brand Data on behalf of the Controller in the course of performing Campaign services. The Processor's sole purpose for processing Brand Data is to complete the agreed content creation and publication services (the "Agreed Purpose") in accordance with the Campaign information provided by the Controller through the Platform. The Processor may not process Brand Data for any other purpose.

本 DPA 適用於處理者在履行 Campaign 服務過程中,代表控制者處理品牌方數據的全部活動。處理者處理品牌方數據的唯一目的是:按照控制者通過平臺提供的 Campaign 信息,完成約定的內容創作與發佈服務(以下簡稱「約定目的」)。處理者不得爲任何其他目的處理品牌方數據。

### 3A. Direct Marketing Data Processing

To the extent that the Controller processes Creator personal data for direct marketing purposes (including, without limitation, the use of Creator data obtained through Phyllo for AI-powered outreach and the sending of collaboration invitations on behalf of Brands), such processing shall fall within the scope of this DPA and shall be subject to the same data protection obligations and safeguards set out herein. The Controller shall ensure that all direct marketing data processing activities are carried out in compliance with Part 6A of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486), the Guidance on Direct Marketing issued by the PCPD, and the Controller's Creator Privacy Policy.

For the avoidance of doubt, the Processor's obligations under this DPA extend to any Brand Data or other personal data that the Processor may access or process in connection with the Controller's direct marketing activities, including but not limited to data relating to Creators who have been contacted through AI-powered outreach.

#### 3A. 直銷數據處理

如控制者為直接促銷目的處理創作者個人資料(包括但不限於將透過 Phyllo 獲取的創作者資料用於 AI 外聯及代表品牌方發送合作邀約),則該等處理應納入本 DPA 的適用範圍,並受本 DPA 所載的相同數據保護義務與保障措施約束。控制者應確保所有直接促銷數據處理活動均遵守香港《個人資料(私隱)條例》(第 486 章)第 6A 部、個人資料私隱專員公署發出的《直接促銷指引》及控制者的《創作者隱私政策》。

為免生疑問,處理者在本 DPA 下的義務延伸至處理者可能因控制者的直接促銷活動而訪問或處理的任何品牌方數據或其他個人資料,包括但不限於與通過 AI 外聯聯繫的創作者相關的數據。

4. Details of Data Processing

4. 數據處理詳情

4.1 Nature and Purpose of Processing

4.1 處理的性質與目的

The Processor processes Brand Data in order to: (a) understand Campaign requirements and create content that meets the Brief; (b) publish promotional content on the agreed social media platforms; and (c) report publication results and performance data to the Controller.

處理者處理品牌方數據,旨在:(a) 理解 Campaign 需求並創作符合 Brief 要求的內容;(b) 在約定社交媒體平臺發佈推廣內容;(c) 向控制者反饋發佈結果與表現數據。

4.2 Data Categories

4.2 數據類別

  • Brand identification information: brand name, logo, brand assets, product name, and description;

品牌標識信息:品牌名稱、Logo、品牌資產、產品名稱與描述;

  • Campaign information: Brief content, promotional requirements, target audience description, budget, and timeline;

Campaign 信息:Brief 內容、推廣要求、目標受衆描述、預算與時間表;

  • Promotional materials: product images, videos, copy, marketing scripts, and sample information;

推廣素材:產品圖片、視頻、文案、營銷話術、樣品信息;

  • Brand contact information (where applicable): Brand representative's name and email address.

品牌方聯繫人信息(如適用):品牌方代表姓名、電子郵件地址。

4.3 Data Subject Categories

4.3 數據主體類別

  • Brand employees or authorized representatives;

品牌方員工或授權代表;

  • Brand's customers or potential customers (only when the Campaign involves targeted promotion).

品牌方的客戶或潛在客戶(僅在 Campaign 涉及定向推廣時)。

4.4 Processing Period

4.4 處理期限

The Processor processes Brand Data from the date of Campaign confirmation until 90 days after the Campaign is completed (based on publication confirmation or the agreed end date, whichever is earlier), or until the Controller requests in writing that the data be deleted or returned, whichever is earlier.

處理者處理品牌方數據的期限爲自 Campaign 確認之日起,至 Campaign 完成(以發佈確認或約定結束日期爲準)後 90 天止,或至控制者書面要求刪除或返還數據之日止(以較早者爲準)。

5. Processor Obligations

5. 處理者義務

The Processor undertakes and warrants:

處理者承諾並保證:

  • to process Brand Data only in accordance with the written instructions provided by the Controller through the Platform (including the Campaign information and this DPA). If the Processor believes that the Controller's instructions violate applicable data protection laws, it shall promptly notify the Controller;

僅按照控制者通過平臺提供的書面指示(包括 Campaign 信息及本 DPA)處理品牌方數據。如處理者認爲控制者的指示違反適用數據保護法律,應立即通知控制者。

  • to ensure that personnel processing Brand Data have assumed appropriate confidentiality obligations and access Brand Data only on a need-to-know basis;

確保處理品牌方數據的人員已承擔適當的保密義務,且僅在「知所必需」的基礎上訪問品牌方數據。

  • to implement appropriate technical and organizational security measures to protect Brand Data against unauthorized or unlawful processing, and against accidental loss, destruction, or damage. Security measures shall meet at least the standards set out in Section 7 of this DPA;

採取適當的技術與組織安全措施,保護品牌方數據免遭未授權或非法處理,以及意外丟失、銷燬或損壞。安全措施至少應達到本 DPA 第 7 條所述標準。

  • to notify the Controller in a timely manner (in any event within 48 hours) of any data subject rights request received (including requests for access, rectification, erasure, or restriction of processing) to the extent permitted by applicable law. The Processor shall not respond to such requests on its own unless otherwise instructed in writing by the Controller;

在適用法律允許的範圍內,及時(無論如何不得超過 48 小時)將收到的任何數據主體權利請求(包括查閱、更正、刪除或限制處理請求)通知控制者。處理者不得自行回應此類請求,除非控制者另有書面指示。

  • to notify the Controller immediately (in any event within 24 hours) upon discovery of a Data Security Incident and to provide all relevant information reasonably requested by the Controller;

在發現數據安全事件後,立即(無論如何不得超過 24 小時)通知控制者,並提供控制者合理要求的全部相關信息。

  • upon completion of the Campaign or upon the Controller's request (whichever is earlier), to delete or return all Brand Data and copies thereof at the Controller's option, unless retention is required by applicable law;

在 Campaign 完成或控制者要求時(以較早者爲準),按照控制者的選擇,刪除或返還所有品牌方數據及其副本,除非適用法律要求保留。

  • to provide information reasonably required by the Controller to demonstrate compliance with its obligations under this DPA, and to allow the Controller or its designated auditor to conduct compliance audits.

應控制者的合理要求,提供證明其遵守本 DPA 義務所需的信息,並允許控制者或其指定的審計機構進行合規審計。

6. Sub-processors

6. 分處理者

The Processor may not engage any third party (sub-processor) to process Brand Data unless such sub-processor is necessary for performing the Campaign services (such as publishing content on social media platforms) and the Controller has been made aware of and consented through the Campaign confirmation process.

處理者不得將品牌方數據的處理委託給任何第三方(分處理者),除非該分處理者系履行 Campaign 服務所必需(如社交媒體平臺發佈內容),且控制者已通過 Campaign 確認流程知曉並同意。

When engaging a sub-processor, the Processor shall enter into a written agreement with the sub-processor to ensure that the sub-processor assumes data protection obligations no less protective than those set out in this DPA. The Processor shall be fully responsible to the Controller for the acts and omissions of the sub-processor.

處理者委託分處理者時,應與分處理者簽訂書面協議,確保分處理者承擔不低於本 DPA 所規定的數據保護義務。處理者應對分處理者的行爲與疏漏向控制者承擔全部責任。

7. Security Measures

7. 安全措施

The Processor shall implement and maintain appropriate technical and organizational security measures, including but not limited to:

處理者應實施並維持適當的技術與組織安全措施,包括但不限於:

  • Access control: only authorized personnel with a legitimate business need may access Brand Data, with multi-factor authentication implemented;

訪問控制:僅限經授權、有合理業務需要的人員訪問品牌方數據,並實施多因素身份驗證;

  • Data encryption: using TLS 1.2 or higher encryption protocols in transit, and industry-standard encryption algorithms for Brand Data at rest;

數據加密:在傳輸過程中使用 TLS 1.2 或更高版本的加密協議,對靜態存儲的品牌方數據使用行業標準加密算法;

  • Physical security: ensuring that devices and premises storing Brand Data have appropriate physical security safeguards;

物理安全:確保存儲品牌方數據的設備與場所具備適當的物理安全防護;

  • Malware protection: installing and maintaining up-to-date anti-virus/anti-malware software on devices used to process Brand Data;

惡意軟件防護:在用於處理品牌方數據的設備上安裝並維護最新的防病毒/反惡意軟件;

  • Data minimization: collecting and retaining only the minimum Brand Data necessary to fulfill the Agreed Purpose;

數據最小化:僅收集與保留爲完成約定目的所必需的最少品牌方數據;

  • Backup and recovery: regularly backing up Brand Data and having the ability to recover data in the event of data loss or damage;

備份與恢復:定期備份品牌方數據,並具備在數據丟失或損壞時恢復數據的能力;

  • Security assessment: regularly evaluating and testing the effectiveness of security measures and making improvements as appropriate.

安全評估:定期評估與測試安全措施的有效性,並適時改進。

8. Data Security Incidents

8. 數據安全事件

The Processor shall establish and maintain a Data Security Incident response process. Upon discovery of a Data Security Incident, the Processor shall:

處理者應建立並維護數據安全事件響應流程。一旦發現數據安全事件,處理者應:

  • notify the Controller within 24 hours of discovery, describing the nature of the incident, the categories and approximate number of data records potentially affected, the categories and approximate number of data subjects potentially affected, the possible consequences, and the remedial measures taken or planned;

在發現後 24 小時內通知控制者,說明事件的性質、可能影響的數據類別與大致數量、可能影響的數據主體類別與大致數量、可能產生的結果,以及已採取或擬採取的補救措施;

  • immediately take reasonable measures to mitigate the adverse impact of the incident and prevent its further escalation;

立即採取合理措施,減輕事件可能造成的不利影響,防止事件進一步擴大;

  • cooperate with the Controller's investigation, preserve logs and evidence related to the incident, and provide supplementary information reasonably requested by the Controller;

配合控制者的調查,保留與事件相關的日誌與證據,並向控制者提供合理要求的補充信息;

  • not disclose any information about the incident to any third party (except as required by law) or to the public without the Controller's prior written consent.

未經控制者事先書面同意,不得向任何第三方(法律另有要求除外)或公衆披露事件相關信息。

9. Cross-Border Data Transfers

9. 跨境數據傳輸

The Processor may not transfer Brand Data to any jurisdiction outside the Hong Kong Special Administrative Region unless: (a) the Controller has given prior written consent; and (b) the Processor has implemented appropriate safeguards as required by applicable data protection laws (such as standard contractual clauses).

處理者不得將品牌方數據轉移至香港特別行政區以外的司法管轄區,除非:(a) 控制者事先書面同意;且 (b) 處理者已採取適用數據保護法律要求的適當保障措施(如標準合約條款)。

10. Audit Rights

10. 審計權

The Controller has the right to audit (either itself or through a designated independent auditor) the Processor's compliance with this DPA. Audits shall: (a) be notified in writing at least 14 days in advance, except in the event of a Data Security Incident or other emergency; (b) be conducted during the Processor's normal business hours; and (c) minimize disruption to the Processor's normal business operations. The Processor shall provide the Controller with information reasonably necessary to demonstrate its compliance with this DPA and shall cooperate with the audit.

控制者有權(自行或通過指定的獨立審計機構)審計處理者遵守本 DPA 的情況。審計應:(a) 提前至少 14 天書面通知,除非發生數據安全事件或緊急情況;(b) 在處理者的正常營業時間內進行;(c) 儘量減少對處理者正常業務運營的干擾。處理者應向控制者提供爲證明其遵守本 DPA 而合理必要的信息,並配合審計。

11. Liability and Indemnification

11. 責任與賠償

The Processor shall be liable for direct losses suffered by the Controller resulting from the Processor's breach of this DPA or applicable data protection laws. Where the Processor's breach of this DPA causes the Controller to suffer any third-party claim, fine, penalty, or sanction, the Processor shall indemnify the Controller for all losses, costs, and expenses (including reasonable attorneys' fees) arising therefrom.

處理者應對因違反本 DPA 或適用數據保護法律而給控制者造成的直接損失承擔責任。處理者違反本 DPA 導致控制者遭受任何第三方索賠、罰款、處罰或制裁的,處理者應賠償控制者因此遭受的全部損失、費用與支出(包括合理律師費)。

12. Term and Termination

12. 期限與終止

This DPA takes effect on the date the Parties confirm it through the Platform and remains in effect until the Creator Service Agreement between the Parties is terminated. Upon termination of this DPA, the provisions of Section 5 (Processor Obligations) regarding data deletion or return, Section 8 (Data Security Incidents), Section 11 (Liability and Indemnification), and Section 13 (Governing Law) shall continue to apply.

本 DPA 自雙方通過平臺確認之日起生效,持續有效至雙方之間的《創作者服務協議》終止爲止。本 DPA 終止後,第 5 條(處理者義務)中關於數據刪除或返還的規定、第 8 條(數據安全事件)、第 11 條(責任與賠償)及第 13 條(適用法律)繼續有效。

13. Governing Law and Dispute Resolution

13. 適用法律與爭議解決

The formation, validity, interpretation, and performance of this DPA are governed by the laws of the Hong Kong Special Administrative Region (excluding its conflict-of-laws rules). Any dispute arising out of or in connection with this DPA shall first be resolved through friendly consultation. If consultation fails, either party may submit the dispute to a court of competent jurisdiction in the Hong Kong Special Administrative Region.

本 DPA 的訂立、效力、解釋與履行,均適用香港特別行政區的法律(不含其衝突法規則)。因本 DPA 引起的或與本 DPA 相關的任何爭議,應首先通過友好協商解決。協商不成的,任何一方可將爭議提交至香港特別行政區有管轄權的法院解決。

14. General Provisions

14. 一般條款

This DPA forms an integral part of and has the same legal effect as the Creator Service Agreement between the Parties. In the event of any inconsistency between this DPA and the Creator Service Agreement, this DPA shall prevail with respect to data processing matters. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

本 DPA 構成雙方《創作者服務協議》的組成部分,與其具有同等法律效力。如本 DPA 與《創作者服務協議》的條款存在不一致,就數據處理事項而言,以本 DPA 爲準。如本 DPA 中任何條款被認定爲無效或不可執行,其餘條款繼續具備完全效力。

15. Contact Information

15. 聯繫方式

If you have any questions about this DPA, please contact the Data Controller through the following means:

如對本 DPA 有任何疑問,請通過以下方式聯繫數據控制者:

  • BeeMatch AI Technology Limited

BeeMatch AI Technology Limited

  • Contact email: yongpeng@beematchai.com

聯繫郵箱:yongpeng@beematchai.com

  • Official website: https://beematchai.com

官方網站:https://beematchai.com

© 2026 BeeMatch.AI