Learn how QwenWork handles data, privacy, and security.
Scope
This document explains how QwenWork (“the Product” or “QwenWork”) collects, uses, stores, and protects user data on the web and desktop. It applies to individual users and organization administrators who grant access to enterprise members.
Data We Collect
To provide the services, the Product processes the following types of information:
- Account and identity information: Username, email address, profile photo, and authentication details such as single sign-on identifiers and enterprise identity information.
- Conversation and task content: Prompts, uploaded files, and generated outputs, such as presentations, documents, webpages, and data-analysis reports.
- Usage data: Feature activity, usage statistics, seat utilization, and operation logs.
- Cloud Drive and Skill Center content: Files, knowledge bases, and workflow configurations that users actively save to their workspace.
- Admin-console data: Usage policies, connector configurations, member permissions, and team knowledge-base rules configured by enterprise administrators.
How We Use Data
We are committed to protecting user data and privacy. Collected data is used only to:
- Process conversations, generate content, execute tasks, and return results.
- Calculate organizational usage and manage seats and quotas.
- Support permission governance, security audits, and compliance management by organization administrators.
- Troubleshoot service issues, improve the product experience, and fulfill legal obligations.
- Understand user needs and optimize the product experience.
Data Storage and Protection
Storage Location
User content and related data are stored in cloud-service environments located in Singapore.
Security Measures
- Encryption in transit: Communications between clients and servers are encrypted using TLS.
- Encryption at rest: Stored data is protected using industry-standard encryption algorithms.
- Access control: Internal access is restricted according to the principle of least privilege. Critical operations require multifactor authentication and approval.
- Audit logging: Administrator actions and system-access logs are recorded for security audits and anomaly detection.
- Vulnerability management: Security scans, penetration testing, and patch updates are performed regularly.
Data Retention and Deletion
- Content deleted by users is removed from their visible workspace after the deletion is completed.
- When an organization closes its account or stops using the service, related data is handled according to applicable laws, regulations, and contractual agreements.
- Some data may be retained for the necessary period to meet compliance, auditing, or dispute-resolution obligations.
Organization Administrators’ Rights and Responsibilities
After subscribing to an Enterprise plan, enterprise administrators can:
- View, configure, and manage members’ usage, seats, and connectors.
- Configure access rules for team knowledge bases.
- Set organization-wide usage policies and permission isolation.
AI-Generated Content
QwenWork uses AI models to assist in generating text, data, charts, code, multimedia, and other content to improve work efficiency. Because AI-generated content may be inaccurate, incomplete, or inconsistent with actual circumstances, generated results are provided for reference only. Users should apply their own professional judgment and independently verify the accuracy, legality, and suitability of all outputs.
To protect information security and ensure compliant use, users should follow these principles:
- Data input requirements: Do not submit highly sensitive personal information, such as ID numbers or bank-account details; core corporate trade secrets, such as unpublished financial data, strategic plans, or source code; unsanitized customer information; access keys; or credentials. The quality and security of input data directly affect the security of generated outputs.
- Content review: AI-generated content should not be used directly in formal contexts. Before submitting reports, publishing externally, uploading to systems, or entering approval processes, users should manually review the factual basis, data accuracy, formatting, and compliance of AI outputs to ensure that the content is accurate, reliable, and consistent with business standards.
- Compliance with internal policies: Before using AI tools, review and follow your enterprise’s or organization’s policies on AI-assisted tools, data security, and information disclosure. Certain industries—including finance, government, and healthcare—have additional data-processing requirements. Users must ensure that their usage complies with applicable regulations and internal policies.
Third-Party Services and Connectors
The Product may interact with other applications or services through connectors. When using a connector, users must confirm the scope and purpose of the data exchange and comply with the connector provider’s terms of service.
Learn More This document is a summary. For the full description of our privacy practices — including your rights, data disclosure, international transfers, cookie practices, and contact information — please refer to the complete QwenWork Privacy Policy. In the event of any inconsistency, the full Privacy Policy shall prevail.