Privacy Policy

AI Archway 瀏覽器擴充功能隱私權政策

本政策說明 AI Archway Browser Extension 如何處理資料。

生效日期2026.09.30

1. 適用範圍

本政策說明中華資安國際股份有限公司(以下稱「我們」)提供的 AI Archway Browser Extension(以下稱「本擴充功能」)如何處理資料。本擴充功能適用於 Google Chrome、Microsoft Edge、Mozilla Firefox 與 Apple Safari。

本擴充功能是企業產品,由您所屬的組織(以下稱「您的組織」)決定是否部署,以及套用哪些防護政策。就本擴充功能處理的資料,您的組織是資料的控管者;我們依您的組織的指示提供服務,屬於受託處理者。

本擴充功能處理的資料,另依您的組織與我們簽訂的服務合約及資料處理協議辦理。

2. 我們處理的資料

您的組織完成註冊前,本擴充功能不處理任何資料。註冊後,本擴充功能只在支援的生成式 AI 網站(例如 ChatGPT、Claude、Gemini、Copilot),以及您的組織明確啟用的內部 AI 網站上運作,處理以下資料:

  1. 註冊與裝置資料:裝置與瀏覽器識別資訊、擴充功能版本、註冊時間,以及裝置最後連線的時間與 IP 位址。
  2. 輸入及輸出之 AI 互動內容:您傳送至上述 AI 網站之文字內容,或 AI 網站回覆之內容。前述內容可能包含個人資料、財務資料、驗證資訊或您的組織定義之機密資料。此類內容將傳送至 Archway 服務進行即時比對、遮罩、阻擋或解罩,並依您的組織設定之政策儲存為稽核紀錄。
  3. 事件與稽核紀錄:使用的 AI 網站、時間、偵測到的敏感資訊類型、採取的動作(提醒、遮罩或阻擋),以及您送出的內容。只有您的組織授權的管理員可以查看。

3. 資料的使用方式

我們只為了本擴充功能的單一用途使用上述資料:依您的組織設定的政策,防止敏感資訊外洩到生成式 AI 工具。具體包括:偵測敏感資訊、提醒您、在送出前遮罩或阻擋、在 AI 回覆中為您還原被遮罩的內容,以及提供組織管理員所需的稽核紀錄。

我們不會販售資料、不會用於廣告或建立個人檔案,也不會用於判斷信用等級或貸款。

本擴充功能對使用者資料的使用,遵守 Chrome 線上應用程式商店使用者資料政策,包括其中的限制使用規定。

4. 資料的分享與傳輸

  • 您的組織:組織指定的管理員可透過 Archway 管理平台查看裝置狀態與稽核紀錄(包含您送出的內容)。
  • 服務供應者:協助我們提供服務的供應商(例如雲端主機)。
  • 法律要求:依法令或主管機關的要求提供。

資料的處理地區,依您的組織選用的服務方案及服務合約約定。

5. 資料保存與刪除

  • 您的裝置上只保存註冊狀態與執行防護所需的設定資料。移除本擴充功能時,這些資料會一併刪除。
  • 送往掃描服務的內容與其他稽核紀錄,保存至您的組織設定的期間屆滿,或服務終止為止。

6. 您的權利

依適用法令(包括中華民國《個人資料保護法》),您可以就您的個人資料行使下列權利:查詢或請求閱覽、請求製給複製本、請求補充或更正、請求停止蒐集處理或利用、請求刪除。由於您的組織為資料控管者,如您欲行使上述權利,請直接聯絡您的組織管理員。若您直接向我們提出請求,我們將轉知您的組織,並於授權與指示之合理範圍內協助您的組織辦理。

如您不提供上述資料,將無法使用本擴充功能的防護功能。

7. 政策變更

我們可能更新本政策,更新後會公布於本頁面並更新生效日期。重大變更將以適當方式通知您的組織。

8. 聯絡我們

如對本政策有任何問題,請聯絡:

Effective date2026.09.30

1. Scope

This policy explains how CHT Security Co., Ltd. ("we", "us") handles data in the AI Archway Browser Extension (the "Extension"). The Extension is available for Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari.

The Extension is an enterprise product. Your organization ("your organization") decides whether to deploy it and which protection policies apply. For the data the Extension processes, your organization is the data controller; we provide the service on your organization's instructions as a data processor.

Data processed by the Extension is also governed by the service agreement and the data processing agreement between your organization and us.

2. Data we process

The Extension does not process any data until your organization completes enrollment. After enrollment, it operates only on supported generative AI websites (such as ChatGPT, Claude, Gemini and Copilot) and on internal AI websites that your organization explicitly enables, and processes the following data:

  1. Enrollment and device data: device and browser identifiers, Extension version, enrollment time, and the time and IP address of the device's most recent connection.
  2. AI interaction content (input and output): text you send to the AI websites above, and content returned by those AI websites. This content may include personal data, financial information, authentication information, or data your organization defines as confidential. It is sent to the Archway service for real-time matching, masking, blocking or unmasking, and stored as audit records according to the policy set by your organization.
  3. Event and audit records: the AI website used, the time, the types of sensitive information detected, the action taken (alert, mask or block), and the content you submitted. Only administrators authorized by your organization can view them.

3. How we use data

We use the data above only for the Extension's single purpose: preventing sensitive information from being disclosed to generative AI tools, according to the policy set by your organization. This includes detecting sensitive information, alerting you, masking or blocking content before it is sent, restoring masked content in AI responses for you, and providing audit records to your organization's administrators.

We do not sell data, use it for advertising or profiling, or use it to determine creditworthiness or for lending purposes.

The use of information received by the Extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

4. Sharing and transfer

  • Your organization: administrators designated by your organization can view device status and audit records (including the content you submitted) in the Archway management platform.
  • Service providers: providers that help us deliver the service (such as cloud hosting).
  • Legal requirements: where required by law or by a competent authority.

The location where data is processed is determined by the service plan your organization selects and the terms of the service agreement.

5. Retention and deletion

  • Your device stores only the enrollment state and the configuration needed to provide protection. This data is deleted when the Extension is removed.
  • Content sent to the scanning service and other audit records are retained until the period set by your organization expires or the service ends.

6. Your rights

Under applicable law (including Taiwan's Personal Data Protection Act), you may exercise the following rights with respect to your personal data: to inquire about or request to review it, to request a copy, to request that it be supplemented or corrected, to request that its collection, processing or use be stopped, and to request its deletion. Because your organization is the data controller, please contact your organization's administrator directly to exercise these rights. If you submit a request to us directly, we will forward it to your organization and assist your organization in handling it to the extent reasonably authorized and instructed.

If you do not provide the data described above, you will not be able to use the Extension's protection features.

7. Changes to this policy

We may update this policy. Updates will be posted on this page with a new effective date. We will notify your organization of material changes in an appropriate manner.

8. Contact us

If you have any questions about this policy, please contact: