Governance
Information Security and Privacy Protection
Emergency Response to Cybersecurity Incidents
The group has formulated the Genertec Universal Medical Group Limited Network and Information Security Emergency Plan specifically for emergency response to cybersecurity incidents. Each year, it participates in cybersecurity drills organized by the Ministry of Public Security, where it responds to external attacks and various information security incidents received during the drills and produces a Security Incident Report. The report requires the closure of each security incident by rectifying it within a specified time frame.
Customer Privacy Protection Policy
Universal Medical attaches great importance to privacy security, respecting and protecting the personal privacy rights of all users of its services, and treating all personal information with caution. The group has integrated its "Privacy Policy" into risk and compliance management, formulated privacy agreements, and standardized procedures for information collection, use, disclosure, storage and exchange, as well as information security assurance. For detailed information, please refer to our Privacy Agreement, which includes the methods of information collection, purposes of information use, disclosure, storage and exchange rules, among other contents.It explicitly states that customers have the right to decide how their personal data is collected, used, retained, and processed, including the option to opt out, require opt-in consent, request access to data held by the Group, request the transfer of customer data to other service providers, and update or delete data. Additionally, customers are clearly informed of the expected retention period for the information collected and used (personal information is retained only for the period necessary to achieve the purposes stated in this privacy policy and within the time limits required by laws and regulations). When disclosing customer information to third parties, prior consent from the customer is obtained, ensuring customers have full data access and control rights, and effectively preventing and addressing data security risks.
The Company adopts a zero-tolerance policy towards unauthorized access, leakage, misuse, unlawful processing of personal information, or any breach of its privacy policy. For confirmed violations identified through investigation, the Company will impose disciplinary and accountability measures depending on the severity of the case, including warnings, internal reprimands, access restrictions, impact on performance appraisal, job transfer, termination of employment or business relationship. Where any violation of laws or regulations is suspected, the case will be referred to the relevant competent authorities in accordance with the law.
Responsible AI
Universal Medical attaches great importance to the compliant and prudent application of artificial intelligence technologies, and integrates AI governance into the Group’s risk management, compliance management, information security and data protection systems. The Group has formulated management policies related to Responsible AI, with the Board of Directors serving as the highest decision-making body. These policies cover the development, procurement, deployment, use, monitoring and retirement of AI systems and tools, ensuring strict compliance with requirements relating to personal information protection, data security and cybersecurity throughout the use and development of AI systems. The Group clearly defines rules for data collection, use, storage, transmission, sharing, deletion and access permission management. Without authorization, personal information, patient information, customer information, trade secrets or sensitive data shall not be entered into external AI tools. AI systems involving sensitive data or important business processes shall be subject to data security and cybersecurity risk assessments, so as to promote the application of AI technologies on the basis of legality, compliance, safety, controllability, fairness, transparency and human-centric principles.
In the use of AI, the Group adheres to the principles of data privacy protection, cybersecurity, fairness and non-bias, transparency and explainability, clear accountability and human oversight. The Group requires AI applications involving personal information, customer information, patient information, trade secrets and other sensitive data to strictly comply with data protection and access permission management requirements, and retains human review and intervention mechanisms for AI outputs in important business scenarios. The Group clearly defines the boundaries of AI systems, and prohibits the use of AI for manipulative behavior, exploitation of personal vulnerabilities, social scoring, unauthorized biometric surveillance, or any other purposes that violate laws, regulations or business ethics.
The Group has established AI application management procedures to control access to and permissions for sensitive AI capabilities, including facial recognition, behavioral monitoring, automated profiling and other functions that may have a significant impact on individual rights and interests. The Group requires AI-generated content, analytical results or AI-assisted decision-making outcomes to be appropriately labelled, with necessary review and traceability records retained. For deployed AI systems, the Group continuously monitors model drift, performance degradation, output errors, bias risks and security vulnerabilities, and makes timely corrections through human review, usage restrictions, model adjustments, data correction or supplier rectification.
The Group pays attention to the impact of AI applications on stakeholders and sustainable development, and regularly assesses the performance of AI systems in terms of fairness, bias risks, information security, privacy protection and environmental impact. The Group also provides feedback and appeal channels for users, employees, customers and other affected parties. Meanwhile, the Group promotes the reduction of resource consumption and environmental footprint during the operation of AI systems. When procuring third-party AI systems, models, cloud services or data center services, the Group incorporates data security, compliance governance, service stability and green and low-carbon performance into supplier assessments.
The Group regularly conducts training related to Responsible AI, covering AI ethics, data privacy, information security, compliant use, risk identification and employee use boundaries, so as to enhance employees’ awareness and capabilities in using AI tools safely, compliantly and responsibly. The Group will continue to improve its AI governance mechanisms and dynamically optimize relevant policies and management measures in line with business development, regulatory requirements and technological changes.
Official Wechat Account
Offical Weibo Account