SOFTLOAF LAB
Cross-border processing notice
Version: 2026-08-01 (separate consent)
Why a transfer is necessary
SoftLoaf uses a Hong Kong account and licensing service and an overseas transactional-email provider for registration, verification, sign-in, password recovery, license and seat management, security, and support. If you decline, the current architecture cannot create or maintain an account. Public browsing and local image processing do not require registration.
Recipient 1: SoftLoaf Hong Kong account service
The recipient is the account service deployed and controlled in Hong Kong by the operator named above; contact support@softloaflab.com. TLS carries email, password digest, consent, session and security records, entitlements, digested device ID, device label/platform/app version, and privacy requests. Purposes and retention match the Privacy notice. Tencent Cloud's Hong Kong region supplies infrastructure; its official privacy contact is https://cloud.tencent.com/online-service.
Recipient 2: Plus Five Five, Inc. (Resend)
Address: 2261 Market Street #5039, San Francisco, CA 94114, USA; privacy contact: privacy@resend.com. Encrypted SMTP/API transfers email address, message metadata, and verification, recovery, or support content to send and receive transactional mail. Resend's DPA states that it processes customer data while the service agreement is active and deletes it within 90 days after termination, except records legally required to remain.
Exercising rights
Email support@softloaflab.com to request information, access, correction, a copy, deletion, or restriction concerning an overseas recipient, or to withdraw this separate consent. We will coordinate the request with the recipient. Withdrawal does not affect prior processing, but may prevent continued account, email, or licensing service.
Risks and safeguards
Overseas laws, supervision, and remedies may differ from Mainland China, and transmission or provider failures can cause disclosure, loss, delay, or unavailability. We minimize transferred fields, do not upload photographs, and use TLS, irreversible password/device digests, access controls, log rotation, encrypted backups, and provider data-protection terms. A personal-information protection impact assessment covers this small-scale, non-sensitive processing.