AMT Sustainability · 全面可持续数字化

Privacy Policy

Effective: 31 May 2026 · Last updated: 31 May 2026

This Privacy Policy explains how AMT collects, uses, shares, stores and protects your personal information when you visit our website or use our products and services, and the rights you have. We operate on the basis of China’s Personal Information Protection Law (PIPL) and Data Security Law, and align with the EU General Data Protection Regulation (GDPR) to provide equivalent protection for overseas business. Please read this Policy carefully before using our services.

1.Overview

This Policy is issued by and the responsibility of AMT (Shanghai Anmo Consulting Management Co., Ltd.) (“AMT”, “we”, “us”), and applies to the websites, web applications, APIs and related products and services we operate (collectively, the “Services”).

When providing SaaS to customers, AMT generally acts as an “entrusted processor / processor” for business data uploaded by customers (such as enterprise carbon and supply-chain data), with the customer as the “personal-information handler / controller”. For personal information of our own website visitors and prospects, AMT acts as the handler / controller.

2.Information we collect

We collect only the information necessary to deliver the Services, in the following categories:

  • Necessary information: name, company, role, work email and phone you actively provide, used to respond to enquiries, deliver Services and perform contracts.
  • Optional information: any other details you choose to provide in form notes, surveys or communications.
  • Automatically collected information: device and browser type, IP address, access logs, and usage data collected via cookies and similar technologies (see the Cookie Policy).
  • Customer business data: data customers upload to the platform, which may contain personal information of their staff or supply-chain contacts, processed under the customer’s control.

We do not actively collect sensitive personal information such as race, religion or biometrics unless we obtain your separate consent or the law requires otherwise.

3.How we use information

We use your personal information on the following lawful bases: necessity to enter into or perform a contract, your consent, compliance with legal obligations, and legitimate interests that do not override your rights.

  • To provide, maintain and improve the Services, and for authentication and account management;
  • To respond to enquiries, provide support and send materials you request (e.g. whitepapers);
  • To send product updates and the regulatory newsletter where you have consented — you may unsubscribe at any time;
  • To ensure security, prevent fraud and abuse, and meet compliance and audit obligations.

4.Sharing and disclosure

We do not sell your personal information. We share information only in the following situations, requiring recipients to apply protections no weaker than this Policy:

  • Sub-processors: vendors necessary to deliver the Services, such as cloud infrastructure, email and monitoring (categories listed under Trust Center · Sub-processors);
  • Legal requirements: disclosure under laws, regulations, regulatory requests or valid legal process;
  • Business transfers: transfers in a merger, acquisition or asset sale, subject to contract and law, with prior notice to you.

5.Cross-border data transfer

Customer data is stored by default in AMT’s data centre within China (Shanghai). Where cross-border transfer of personal information is genuinely necessary, we adopt compliant routes under the PIPL and cross-border assessment rules — including entering into and filing the standard contract, relying on the Shanghai FTZ cross-border negative-list pilot, or completing a security assessment where applicable, together with a Personal Information Protection Impact Assessment (PIPIA).

For overseas business subject to the GDPR, we provide appropriate safeguards aligned with Chapter V of the GDPR. See Trust Center · Cross-Border Data Compliance.

6.Data security

We maintain an ISO/IEC 27001 information-security management system and apply technical and organisational measures appropriate to the risk:

  • Encryption at rest and in transit, with key management;
  • Least-privilege access control and multi-factor authentication;
  • Audit logging, continuous monitoring and vulnerability management;
  • Tiered incident response, with timely notification after a confirmed incident as required by law.

7.Data retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or longer where required by law. After contract termination, customer business data is subject to an agreed 30 / 90 / 180-day deletion window, after which we securely delete or anonymise it, save where the law requires otherwise.

8.Your rights

Within the limits of applicable law, you have the following rights over your personal information:

  • Right to be informed and of access: to know and obtain how we process your personal information;
  • Right to rectification: to have inaccurate or incomplete information corrected;
  • Right to erasure: to request deletion in the circumstances provided by law;
  • Right to restrict and object: to restrict or object to certain processing;
  • Right to portability: to obtain or transfer your information in a structured, common format;
  • Right to withdraw consent: to withdraw consent at any time, without affecting processing before withdrawal.

You can exercise these rights via privacy@amt.com.cn; we will verify and respond within the statutory timeframe.

9.Children’s privacy

Our Services are intended for business customers, not for individuals under 16, and we do not knowingly collect their personal information. If you believe we may have done so, please contact us to delete it.

10.Cookies and tracking

We use cookies and similar technologies to keep the site working and improve your experience. By default, only necessary cookies are enabled; analytics and marketing cookies are enabled only with your consent. You can manage these at any time via the cookie preferences or your browser. See the Cookie Policy.

11.Third-party links and services

Our website may contain links to third-party sites or services (such as linked products like the Trusted Data Space). These third parties have their own privacy policies; we are not responsible for their content or processing, and we encourage you to review their policies before use.

12.Updates to this Policy

We may update this Policy from time to time. For material changes, we will notify you in advance via a website notice or other appropriate means. The updated Policy takes effect on the date it is posted; please review it periodically.

13.Contact us

For any questions, complaints or rights requests about this Policy or our processing, please contact our data-protection contact:

Data-protection email: privacy@amt.com.cn · General enquiries: sustainability@amt.com.cn · Phone: +86 021-8016-0600 · Office: Shanghai.

14.Governing law and disputes

This Policy is governed by the laws of the People’s Republic of China. Disputes arising from it shall first be resolved amicably; failing that, they shall be submitted to the competent People’s Court at AMT’s principal place of business (Shanghai).