1. 適用範圍
本政策說明 KCRDoc(「我們」)於你使用 kcrdoc.com 網站、KCRDoc 主控台,以及經分享/簽署/表單連結存取之訪客頁面時,如何收集、使用及保護個人資料。
2. 我們收集的資料
- 帳戶資料:姓名、電郵、角色與權限設定。
- 客戶內容:你或你的機構上傳、掃描入庫之文件,及其衍生資料(OCR 全文、分類標籤、風險評分、水印代碼)。
- 使用與稽核記錄:操作事件、時間戳、IP 位址、瀏覽器資訊 — 呢啲記錄係產品合規功能嘅一部分。
- 訪客連結事件:經分享或簽署連結存取時,成功與被拒之存取事件(包括 IP)會被記錄,用於鑑識追溯。
- Cookies:僅用於登入工作階段;語言偏好儲存於瀏覽器本機。我們不使用廣告追蹤。
3. 資料用途
我們處理上述資料僅為:提供服務功能(OCR、分類、索引、搜尋、水印、分享、簽署、工作流);安全防護與稽核;發送服務通知(如 OTP、簽署邀請);以及維持服務可靠運作。
4. AI 處理
啟用 AI 功能時,文件文字或影像可能傳送至我們委託之雲端 AI 模型供應商(作為次處理者)進行分類、風險評估或語意索引,僅限於提供服務所需。相關合約限制其僅可為提供本服務而處理該等資料。
5. 儲存位置與安全
服務託管於 AWS(新加坡區域)。傳輸以 TLS 加密;每個租戶擁有獨立資料庫與儲存樹,配合角色權限(RBAC)與先行寫入稽核日誌。
6. 保存期
客戶內容按租戶設定之保存政策處理;受法律封存之記錄於封存解除前不會刪除。稽核日誌為合規目的按政策保留。
7. 資料披露
我們不出售個人資料。資料僅於以下情況披露:予提供基礎設施之次處理者(雲端託管、AI 模型、郵件遞送);或法律要求時。
8. 你的權利
你可經你的租戶管理員(或直接聯絡我們)查閱、更正或刪除你的個人資料。訪客(分享/簽署連結使用者)亦可聯絡我們行使上述權利。
9. 政策修改
我們可不時修訂本政策,修訂後將於本頁公布並更新生效日期。
10. 聯絡
私隱查詢請聯絡 KCRDoc:contact@kcrdoc.com。
1. Scope
This policy explains how KCRDoc ("we") collects, uses and protects personal data when you use the kcrdoc.com website, the KCRDoc console, and guest pages reached via share / signing / form links.
2. What we collect
- Account data: name, email, role and permission assignments.
- Customer content: documents you or your organization upload or scan in, and data derived from them (OCR text, classification labels, risk scores, watermark tokens).
- Usage and audit records: action events, timestamps, IP addresses, browser information — these records are part of the product's compliance function.
- Guest link events: when a share or signing link is accessed, granted and denied access events (including IP) are recorded for forensic traceability.
- Cookies: used only for the login session; language preference is stored locally in your browser. We do not use advertising trackers.
3. How we use data
We process the above solely to: provide the Service (OCR, classification, indexing, search, watermarking, sharing, signing, workflows); protect and audit the Service; send service notifications (e.g. OTP codes, signing invitations); and keep the Service reliable.
4. AI processing
When AI features are enabled, document text or images may be sent to our contracted cloud AI model providers (as subprocessors) for classification, risk assessment or semantic indexing, strictly as needed to provide the Service. Our agreements restrict them to processing such data only to provide the Service.
5. Storage and security
The Service is hosted on AWS (Singapore region). Transport is TLS-encrypted; each tenant has its own database and storage tree, enforced with role-based access control and write-ahead audit logging.
6. Retention
Customer content is handled per your tenant's retention policy; records under an active legal hold are not deleted until the hold is released. Audit logs are retained per policy for compliance purposes.
7. Disclosure
We do not sell personal data. Data is disclosed only to infrastructure subprocessors (cloud hosting, AI models, email delivery) or where required by law.
8. Your rights
You may access, correct or delete your personal data through your tenant administrator, or by contacting us directly. Guests (share / signing link users) may also contact us to exercise these rights.
9. Changes
We may revise this policy from time to time; revisions will be posted on this page with an updated effective date.
10. Contact
Privacy enquiries for KCRDoc: contact@kcrdoc.com.