PMTSoul
简体中文 繁體中文 English 日本語 한국어 Deutsch Español Português Русский

Privacy Policy

Effective: 27 July 2026Last updated: 27 July 2026
Privacy Policy Terms of Service

Contents

  1. About this policy
  2. Information we collect
  3. How we use information
  4. Use of AI models
  5. Cookies and local storage
  6. How we share information
  7. International transfers
  8. Retention
  9. Security
  10. Your rights
  11. Regional disclosures
  12. Children
  13. Changes to this policy
  14. Contact us

1. About this policy

PMTSoul Limited (“PMTSoul”, “we”, “us”) provides an Agent operating system for businesses: you connect your company’s materials, workflows and tools, and digital employees carry out company tasks under your authorisation. This policy explains what information we collect while providing that service, how we use it, who we share it with, and how you can control it.

It applies to the websites, workspace, mobile pages and related APIs under pmtsoul.com, pmtsoul.com.cn, tasks.pmtsoul.com and their subdomains.

This policy does not cover how third-party platforms you connect through PMTSoul — such as WeChat Official Accounts, advertising platforms, ERP systems, or your own domain email provider — process data inside their own systems. Those are governed by their respective privacy policies.

If you use PMTSoul through your employer, your company decides what data is uploaded and who may access it, and we process that data on your company’s instructions.

The service is operated by two entities. When you use pmtsoul.com and its subdomains, the controller is PMTSoul Limited; when you use pmtsoul.com.cn, the controller is 北京源词人工智能科技有限公司 (Beijing). Both process personal information under the same rules set out in this policy; their contact details are in section 14.

2. Information we collect

2.1 Information you provide

  • Account information: your email address; if you sign in with Google, the account identifier, email and basic profile Google returns to us. We use email verification codes or third-party sign-in, and do not store a password for your account.
  • Company details: company name, one-line description, industry, logo and representative images, website domain, and other information you enter during setup and in settings.
  • Knowledge base materials: documents, images, audio, video and text you upload, and links you submit. Audio is transcribed into text so digital employees can search and cite it. Links you submit are stored as entries only; we do not crawl the pages they point to.
  • Tasks and instructions: the tasks you create or install, the instructions you give digital employees, conversations, and your approval and confirmation decisions.
  • Integration configuration: to let digital employees act in external systems on your behalf, you may configure parameters and credentials for WeChat Official Accounts, ERP systems, advertising platforms, social accounts, company sending domains and similar. Credentials are stored encrypted and decrypted only to run tasks you have authorised.
  • Email content: the platform provides a mailbox for your company. Messages sent and received through it — sender, recipients, subject, body and attachments — are stored so digital employees can handle and follow up on customer correspondence.
  • Order and billing information: subscription and credit purchase records, order amounts and status. Payments are handled by payment providers such as WeChat Pay and Alipay. We do not collect or store your full card number, payment account password or equivalent payment credentials.
  • Information you send us directly: for example in enquiries, feedback or rights requests.

2.2 Information collected automatically

  • Device and access logs: IP address, browser and device type, operating system, language and time zone, access times, request paths and request identifiers. Used to keep the service available and secure.
  • Usage records: actions you take in the product (starting a task, enabling full agency, uploading material), and which features you use.
  • Execution and audit records: for each digital-employee action, the time, steps, duration, credits consumed, result and any errors. Auditability is part of the service — it is what lets you trace who did what, and when.
  • Cookies and local storage: see section 5.

2.3 Information from third parties

  • Identity providers: when you sign in with Google, Google returns your account identifier and email.
  • People who contact you: the content of emails others send to your company mailbox.
  • Payment providers: order payment status and transaction references (never full payment credentials).
  • Platforms you connect: once you authorise them, connected platforms may return campaign data, publishing results, orders, inventory and other business data.

3. How we use information

PurposeInformation involved
Providing the service: giving digital employees company context, running tasks, producing outputsCompany details, knowledge base, tasks and instructions, integration configuration, email content
Authentication and account security: sign-in, session management, detecting abnormal accessAccount information, device and access logs
Billing and quota accounting: subscription status, deducting and reconciling credits and night-shift quotaOrder and billing information, execution records
Notifications: task completion or failure, items awaiting your confirmationAccount information, push subscriptions, execution records
Improving the service and troubleshooting: diagnosing errors, improving performanceUsage records, access logs, execution and audit records
Security and compliance: preventing abuse, fraud and unlawful use; meeting legal obligationsAccess logs, execution and audit records, account information

Training models on your data: off by default.

Without your company’s explicit authorisation, we do not use your business data, knowledge base materials, email content or task outputs to train general-purpose models for the public.

If we later offer a feature that improves your own company-specific capability using your data, it will be off by default, require you to switch it on, and be withdrawable at any time — after which we stop that use.

We do not use your personal information for purposes unrelated to those above. If we need to extend the purposes, we will tell you separately and obtain your consent where the law requires it.

4. Use of AI models

To carry out a task, a digital employee sends the context that task requires — the instruction, relevant knowledge base excerpts, the email or copy being worked on — to an AI model for inference, and receives the result.

  • Model neutrality: we are not tied to a single model vendor. We route between multiple providers based on task type, cost and security level, which may include providers inside and outside your region.
  • Minimum necessary: only the content needed for that task is sent. We do not hand your whole knowledge base or mailbox to a model.
  • Not used for their training: we require model providers to use the content they receive only to return that inference result, and not to train their models on it.
  • Outputs need review: model output can be inaccurate or incomplete. Actions that send, publish or spend go through confirmation steps; the exact scope follows the permission and approval settings in the product.
  • Private deployment: enterprise arrangements can specify model deployment regions or private inference nodes separately.

5. Cookies and local storage

We use cookies and browser storage for the following, all either necessary to run the service or to improve your experience:

  • Session and sign-in state: keeping you signed in and preventing session hijacking.
  • Preferences: language and interface choices.
  • Local cache: caching workspace data so pages open faster; cleared when you switch accounts or sign out.
  • Push subscriptions: stored when you enable task notifications.

We do not use third-party advertising trackers. You can clear or block cookies in your browser, but sign-in and some features may then stop working.

6. How we share information

We do not sell your personal information. We share it only in these situations:

  • Your company and team members: authorised members of the same company workspace can see that company’s materials, tasks and outputs. The scope is set by your company’s permission settings.
  • Infrastructure providers: cloud and network providers used to host, transmit and store data — including Cloudflare, and mainland-China cloud providers serving pmtsoul.com.cn.
  • AI model providers: see section 4.
  • Email delivery providers: to send and receive mail for your company.
  • Payment providers: WeChat Pay, Alipay and similar, to collect and reconcile payments.
  • Platforms you connect: publishing or sending on your instruction to WeChat Official Accounts, advertising platforms, social platforms and others.
  • Legal requirements: where required by law or by a lawful request from a judicial or administrative authority, or where necessary to protect the rights of PMTSoul, our users or the public.
  • Corporate transactions: in a merger, acquisition or transfer of assets, information may move with the business. We will require the recipient to remain bound by this policy and will notify you where the law requires.

We give these providers only the information they need to perform their function, and require by contract that they process it on our instructions, apply appropriate security measures, and use it for nothing else.

7. International transfers

PMTSoul serves businesses in several countries and regions, and our servers, providers and team are located in different jurisdictions. Your information may therefore be transferred to, and processed in, places outside your own region.

  • The international site (pmtsoul.com) runs on a globally distributed network, and data may be processed at nodes in several countries.
  • The mainland-China site (pmtsoul.com.cn) is served from nodes inside mainland China. Where personal information is provided outside mainland China, we follow the notice, consent and compliance procedures required by the Personal Information Protection Law and put contractual safeguards in place.
  • For transfers out of the European Economic Area, the United Kingdom or Switzerland, we rely on Standard Contractual Clauses or another mechanism permitted by law.

8. Retention

  • Account and company data: kept while your account is active, so the service keeps working.
  • Knowledge base, email and task outputs: kept until you delete them or close your account.
  • Execution and audit records: kept so that activity remains traceable and reconcilable; these records are part of the service itself.
  • Transaction and invoice records: kept for the period required by applicable tax and accounting rules.
  • Access logs: kept as long as needed for security and troubleshooting, then deleted or anonymised.

After you close your account we delete or anonymise your personal information within 90 days, except where law requires us to keep it. Copies on backup media are overwritten within the normal backup rotation.

9. Security

  • TLS encryption in transit throughout.
  • Credentials for third-party platforms are stored encrypted and decrypted only to run tasks you have authorised.
  • Tenant isolation per company, so one company’s data is not visible to another; local caches are cleared when accounts change.
  • Role-based access control, with internal access on a need-to-know basis.
  • Sensitive fields are redacted where content is displayed or sent outward.
  • Audit records for significant actions, showing who acted, when, and with what result.
  • Confirmation and approval steps for high-risk actions, so nothing goes out without authorisation.

No system is perfectly secure. If a personal-data incident occurs that may affect your rights, we will notify you and the relevant regulator as required by applicable law, and explain the impact and our response. Please keep your sign-in email and devices secure.

10. Your rights

Subject to applicable law, you have the right to:

  • Be informed and access: understand how we process your personal information and obtain a copy.
  • Rectify: correct information that is inaccurate or incomplete.
  • Erase: ask us to delete your personal information where the conditions are met.
  • Portability: where technically feasible, have your personal information transferred to a recipient you name.
  • Withdraw consent: where processing is based on consent, withdraw it at any time. Withdrawal does not affect processing carried out beforehand.
  • Restrict and object: restrict or object to our processing in the circumstances the law provides.
  • Close your account: stop using the service and ask us to delete the associated data.
  • Automated decisions: digital employees act autonomously according to settings you or your company choose. You can stop full agency at any time, turn autonomous execution off for a single task, or switch to confirming each item manually. Where an automated decision significantly affects you, you may ask for an explanation and refuse a decision made solely by automated means.

You can exercise most of these rights directly in the product — deleting material, turning off autonomous execution, closing your account — or by contacting us using section 14. To protect your account we may need to verify your identity first. We respond within the period the law allows, and explain our reasons if we cannot meet a request.

Where the data was uploaded by your company, we may need to pass your request to that company and assist them in handling it.

11. Regional disclosures

Mainland China

We process personal information under the Personal Information Protection Law. Our legal bases include necessity for entering into and performing a contract to which you are a party, compliance with legal obligations, and your separate consent (for example when providing personal information outside mainland China or processing sensitive personal information). You may raise requests through our contact details, and you may also complain to the authority responsible for personal information protection.

European Economic Area, United Kingdom and Switzerland

Our legal bases for processing personal data include performance of a contract, compliance with legal obligations, our or a third party’s legitimate interests (such as keeping the service secure and preventing abuse), and your consent. You have the right to lodge a complaint with your local data protection authority.

Korea

We process personal information under the Personal Information Protection Act (개인정보 보호법). You may request access, correction, deletion and suspension of processing, and may seek dispute resolution through the Personal Information Protection Commission (개인정보보호위원회) or the Personal Information Infringement Report Centre.

Japan

We process personal information under the Act on the Protection of Personal Information (個人情報の保護に関する法律). You may request disclosure, correction, addition, deletion, suspension of use, or suspension of provision to third parties.

12. Children

PMTSoul is a service for businesses and organisations and is not directed at children. We do not knowingly collect personal information from children under 14, or under any other age set by applicable law. If we learn that we have collected such information without valid guardian consent, we delete it promptly. If you believe we may hold such information, please contact us using section 14.

13. Changes to this policy

We may update this policy as our business, technology or legal obligations change. The updated version is published on this page and the “Last updated” date at the top is revised. If a change materially alters the purposes, methods or categories of personal information processed, we will notify you in the product or by email; where the law requires consent, we will obtain it again.

14. Contact us

For questions, comments or requests about this policy or how we handle personal information:

If you use pmtsoul.com
Controller
PMTSoul Limited
Registered address
Room 1603, 16/F, Allied Kajima Building, 138 Gloucester Road, Wan Chai, Hong Kong
Email
service@pmtsoul.com
If you use pmtsoul.com.cn
Controller
北京源词人工智能科技有限公司
Registered address
北京市海淀区中关村东路123号4号楼2层北侧4583室
Website filing
京公网安备11010802049186号
Email
service@pmtsoul.com

We reply within a reasonable time and no later than the period required by applicable law.

PMTSoul home Terms of Service Sign in
© 2026 PMTSoul Limited. All rights reserved.
京公网安备11010802049186号