About GDPR
Introduction to GDPR
On May 25, 2018, the EU's General Data Protection Regulation (GDPR) officially took effect. GDPR is regarded as the strictest and most detailed law ever enacted to protect the security of user data.
With the growing demand for going global, Chinese companies expanding overseas will face GDPR regulation in data collection, processing, and application.
GDPR mainly protects the personal data of EU users. Any app or game that provides services to the EU should comply with GDPR.
GDPR defines two roles: the data controller (Controller) and the data processor (Processor). As the provider of a data processing tool (Agentic Engine, or AE for short), ThinkingAI doesn't access the data of customers or their users. When our customers use AE, they are both data processors and data controllers, and both roles are subject to GDPR. When you use our products, we will do our best to help you achieve GDPR compliance and avoid potential risks.
As a data controller, you are responsible for complying with the six principles set out in GDPR. Failure to comply with the following principles leads to liability:
- Lawfulness, fairness and transparency: Personal data must be processed lawfully, fairly, and transparently
- Purpose limitation: Collected data can be used only for specified purposes
- Data minimisation: Collect only data that is necessary and meaningful
- Accuracy: Data must be accurate and up to date, and there must be ways to update or delete inaccurate information
- Storage limitation: Data must be deleted promptly once the purpose of processing has been fulfilled
- Integrity and confidentiality: Data must be stored securely, unauthorized access to data must be prevented, and data must be protected against damage or loss
In addition, you must protect the following rights of users:
- Right to be Informed: The data controller must provide users with information about the data controller, the types of personal data, the purposes of processing the data, the legal basis, and so on
- Right of access: Users can obtain their personal data and have their personal data processed
- Right to rectification: Users have the right to correct inaccurate personal data
- Right to erasure: Users have the right to delete their personal data
- Right to restriction of processing: In certain cases (such as when data is inaccurate), users can restrict the processing of their personal data
- Right to data portability: Users can transfer their personal data to another data controller
- Right to object: Users can withdraw their earlier consent to the processing of their personal data
- Right not to be subject to a decision based solely on automated processing, including profiling: Users must be informed whether their personal data will be used in automated decision-making (including user profiling), and have the right to refuse the use of their data by these systems
Also note that data collection requires user consent. Consent must be clear and explicit, and users can withdraw their earlier consent based on the "right to object."
As a professional service provider, ThinkingAI is committed to providing efficient and compliant solutions that help Chinese companies grow their overseas business. The following are ThinkingAI's compliance measures and recommendations for the core content of GDPR:
GDPR compliance measures
Fully customizable collection to ensure compliant data collection
On the data collection side, AE provides a fully customizable collection solution. This means you can decide which user information and behavior data to collect based on your actual needs and business scope. All data collection solutions provided by AE, including but not limited to client SDKs, server SDKs, and the data integration tool LogBus, fully support the principles above and never force the collection of any data related to user privacy. When developers need to collect client-related user data for business purposes, the user's client also shows a related prompt, which protects the user's right to be informed. For details about data collection solutions, see the Data Collection Guide.
We also recommend that, when your collection goals are clear, you use only the custom collection features provided by AE to collect the minimum set of data that meets your needs, in line with the "data minimisation" principle.
Support for updating, deleting, and transferring user data
On the data collection side, AE supports updating and deleting specified user data with methods such as user_set and user_del. We also provide the setTrackStatus method, which pauses all data reporting from a client. You can call this API when a user doesn't consent to data collection.
For data that AE has already received and stored, you can use the data deletion tool provided by AE to delete the user data and related event data of specific users. For details, see Data deletion tool.
For data that has been stored, AE provides multiple export methods, such as exporting data through the API.
In summary, building on the custom collection described above, AE supports updating, deleting, and transferring user data as developers' collection needs and users' actual needs change, so that you can provide users with the "right to rectification," "right to erasure," and "right to data portability" set out in GDPR.
Transparent, auditable, highly available, and highly reliable throughout the data lifecycle
AE is a user behavior analytics tool that integrates data collection, ingestion, processing, storage, computation, and application. Every stage of the data lifecycle is transparent and auditable. AE supports access to and operations on all data components at each stage, which ensures that every step of any piece of data, from generation to application, is traceable.
If, for specific reasons, a stage of the system needs to be audited during actual data use, ThinkingAI will provide technical support as far as possible to keep the whole process transparent.
AE has also achieved high availability and high reliability across all components, which ensures the integrity of data services and data storage, in line with the "integrity and confidentiality" principle.
Other recommendations
At the product level, ThinkingAI is always committed to helping customers achieve GDPR compliance. We also recommend that our customers pay more attention to user privacy. The following are some recommended measures at the developer level
A. Write and publish a privacy policy
We strongly recommend that you write a privacy policy for your product and include standard clauses on GDPR compliance in it. This helps your users better understand your product's privacy protection policy.
B. Protect users' right to be informed
Your product must present a clear request for consent to data collection, and data can be collected only after the user consents. This ensures that users know when their data is being collected, rather than having it collected by default.

