Privacy Policy
Last updated: August 15, 2026 | Effective Date: August 15, 2026
This document is a standard template. The legally binding version is the document signed by both parties with Super Route.
1. Introduction and Scope
Super Route ("we", "us", "our") respects and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information (Personal Information / personal data), as well as the rights you have over your own data.
This Policy applies to the personal information relating to you that we process when you access and use the Super Route platform (including the website, applications, APIs, and related services) by any means.
If you use the Super Route Institutional services on behalf of an organization, the data processing arrangement between your organization and Super Route is governed by the Data Processing Agreement (DPA) signed by both parties, and this Policy applies as a supplement.
This Policy does not apply to third-party websites or services linked from the Super Route platform. For such external resources, please refer to their respective privacy policies.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: name, email address, organization name, job title, etc., provided during registration.
- Uploaded content: documents you upload to the platform for analysis (business plans, research reports, financial statements, data room materials, etc.), financial data, investment memo drafts, etc.
- Communication records: communications between you and our customer service, sales, or technical support teams.
- Pilot application information: organization type, team size, use case preferences, etc., provided when booking a demo.
2.2 Information Collected Automatically
- Device and technical information: browser type and version, operating system, device identifiers, screen resolution, language settings.
- Usage logs: access times, page navigation paths, feature usage frequency, search queries, and records of actions taken.
- Cookies and local storage: see the Cookie Policy for details.
2.3 Information from Third-Party Sources
- Public data: industry reports, corporate registration information, market data, etc., obtained from lawful public sources.
- Enterprise customer authorization: personnel and project information synced from the organization's internal systems after authorization by the organization's administrator.
3. How We Use Information
We process your personal information only within the following lawful purposes:
- Providing and improving services: executing AI analysis tasks, generating investment research output, and maintaining platform functionality and performance.
- Account management: creating and managing your user account, identity verification, and access control.
- Security and compliance: detecting and preventing fraud, abuse, and security threats; fulfilling legal, regulatory, and compliance obligations.
- Customer support: responding to your inquiries, troubleshooting, and technical service requests.
- Product optimization: prioritizing features, improving user experience, and optimizing performance based on usage data (using aggregated and anonymized data).
- Communications and notifications: sending service change notices, security alerts, and product updates and industry news that you have expressly consented to receive.
- Legal requirements: processing necessary to comply with mandatory requirements of laws, regulations, regulatory authorities, and law enforcement.
We will not use your personal information for purposes unrelated to those described in this section. If we need to expand the purposes of processing, we will obtain your consent separately.
4. Information Sharing and Disclosure
We do not sell your personal information. We may share it with third parties only in the following limited circumstances:
- Sub-processors: engaging strictly vetted third-party service providers to process specific data as necessary to perform the services (such as cloud infrastructure hosting and email delivery). All sub-processors are bound by the DPA; see Appendix C of the Data Processing Agreement for details.
- Legal and regulatory requirements: disclosure required by laws, regulations, court orders, regulatory investigations, or law enforcement requests.
- Security incident response: notifying affected users, regulatory authorities, and necessary security partners when a security incident is discovered.
- Business reorganization: in the event of a corporate reorganization such as a merger, acquisition, or asset sale, personal information may be transferred as part of the transferred assets, and we will require the successor to continue to comply with this Policy.
Except as described above, we will not share your personal information with any third party unless we obtain your explicit consent.
5. Data Storage and Cross-Border Transfer
Super Route stores data by default in data centers within the People's Republic of China. For Institutional customers, we support a Private Deployment option under which data can reside entirely within an environment within China designated by the customer, ensuring "data does not leave the territory."
If the use of specific third-party sub-processor services involves cross-border data transfer, we ensure compliance through one of the following mechanisms:
- European Union Standard Contractual Clauses (SCC);
- China's standard contract for the cross-border transfer of personal information (pursuant to Article 38 of the Personal Information Protection Law);
- data protection certification mechanisms of the relevant country or region.
We will not transfer your personal information outside the territory without providing appropriate legal safeguards.
6. Security Safeguards
We adopt industry-leading technical and organizational measures to protect your personal information, including but not limited to:
- Compliance certifications: certified under SOC 2 Type II and ISO 27001, with periodic independent third-party audits.
- Encryption: TLS 1.2+ encryption in transit; AES-256 encryption for data at rest.
- Access control: role-based Principle of Least Privilege, with multi-factor authentication (MFA) required for all production environment access.
- Data minimization: collecting only the data necessary for and directly related to the service, and promptly deleting or anonymizing data once processing is complete.
- Security monitoring: 24/7 security log monitoring and anomalous behavior detection systems.
- Incident response: establishing and maintaining an Incident Response Plan, with periodic drills and updates.
- Personnel management: all employees sign confidentiality agreements and receive regular security and privacy training.
Despite the measures described above, no information system can be absolutely secure. We will continue to evaluate and improve our security protections and will notify you promptly if a security incident is discovered.
7. Data Retention Period
We retain your personal information only for the period necessary to achieve the purposes of processing, or for the minimum retention period required by laws and regulations. The specific rules are as follows:
- Account information: retained for the duration of the account; deleted within 30 days after account cancellation, unless otherwise required by laws and regulations.
- Uploaded content and analysis output: retained during the service term; a 30-day data export window is provided after contract termination, after which the data is deleted.
- Usage logs: retained for up to 12 months, then anonymized or deleted after use for security auditing and product optimization.
- Communication records: retained for 6 months after the relevant issue is resolved.
- Legal requirements: records required to be retained for extended periods under tax, regulatory, or other legal requirements are retained for the statutory minimum period.
8. Your Rights
Under applicable data protection laws and regulations (including the Personal Information Protection Law of the People's Republic of China and the EU GDPR), you have the following rights:
- Right of access: you have the right to know what personal information relating to you we process and to request a copy.
- Right to rectification: you have the right to request that we correct inaccurate or incomplete personal information.
- Right to erasure: under certain conditions (such as when the purposes of processing have been fulfilled, you withdraw consent, or processing is no longer lawful), you have the right to request that we delete your personal information.
- Right to data portability: you have the right to request that your personal information be exported in a structured, commonly used format, or transferred to another service you designate.
- Right to withdraw consent: where we process information based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to restrict processing: in certain circumstances, you have the right to request that we restrict the processing of your personal information.
- Right to lodge a complaint: if you believe our processing of your personal information violates applicable law, you have the right to lodge a complaint with the competent supervisory authority.
To exercise the above rights, please submit a request via privacy@superroute.io or contact the Super Route administrator within your organization. We will respond within 15 business days of receiving your request.
9. Cookies and Similar Technologies
We use cookies and similar local storage technologies to provide, protect, and improve our services. For information about the types of cookies we use, the specific list, and how to manage them, please refer to our Cookie Policy.
10. Third-Party Links
The Super Route platform may contain links to third-party websites or services. These third parties have their own privacy policies, and we are not responsible for their data processing practices. We recommend that you read their privacy policies before accessing any third-party website.
11. Minors
Super Route's services are intended for professional investment institutions and are not directed at minors (individuals under the age of 18). We do not knowingly collect personal information from minors. If we discover that we have inadvertently collected a minor's data, we will delete it promptly.
12. Policy Updates
We may update this Privacy Policy from time to time. The updated version will be posted on this page and the "Last updated" date will be revised. For material changes (such as new data processing purposes or changes to the scope of sharing), we will notify you through platform notices or email.
If you continue to use the Super Route services after a policy update, you will be deemed to have accepted the updated policy. If you do not agree with the updated content, you have the right to stop using the services and request deletion of your data.
13. Contact Us
If you have any questions or comments about this Privacy Policy, or wish to exercise your data rights, please contact us through the following channels:
- Privacy email: privacy@superroute.io
- Data Protection Officer (DPO): dpo@superroute.io
- General support: support@superroute.io
We will respond within 15 business days of receiving your request.