Our engineering work usually involves client source code, data extracts and access credentials rather than personal data about individuals. This page sets out how Sweet Intelligence Limited handles the personal data it does hold, under the Personal Data (Privacy) Ordinance (Cap. 486).
1. Who we are
This policy is issued by Sweet Intelligence Limited, a company incorporated in Hong Kong on 21 May 2025 under the Companies Ordinance (Cap. 622), company number 78185856, with its office at Flat/Rm 2108B, Champion Tower, Three Garden Road, Central, Hong Kong. In this policy, "we", "us", or "our" refers to this company, and "the Site" refers to sweetintelligence.tech.
We are the data user for personal data collected through the Site and through our application, system and agent development, research and technical consulting engagements. This policy follows the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles.
2. What we collect
We collect only what we need, by lawful and fair means, and we tell a data subject what we are collecting at the time we collect it. Supplying personal data to us is voluntary. If you choose not to supply the contact details or engagement materials we ask for, we may be unable to answer your enquiry or to deliver the services you have engaged us to provide. In practice that means:
- Contact details you give us. Name, organisation, job title, telephone number, postal address, and any message you send us.
- Engagement materials. Documents, data, and materials you share with us during a project. We treat these as confidential client information. The client agreement governs how we use and share them.
- Technical data. When you visit the Site, your browser sends information such as your IP address, user agent, referrer, and the page requested. Our hosting infrastructure keeps these in server logs briefly to keep the Site running and secure. Each page also loads fonts from Google Fonts, so your browser sends your IP address and browser information to Google when a page loads. Google handles that information under its own privacy policy.
The Site uses no analytics cookies, advertising pixels, or third-party tracking. If that changes, we will update this policy before the change takes effect.
3. Why we collect it
We collect personal data for these purposes:
- To respond to enquiries you send us.
- To deliver the services you have engaged us to provide.
- To meet legal, tax, and audit obligations.
- To keep the Site and our systems secure.
We use personal data for those purposes and for purposes directly related to them. DPP3 requires the data subject's consent before personal data is used for a new purpose, so if a new purpose arises we will ask you first. Access inside the company is limited to people who need the data for their work.
4. Direct marketing
We do not use personal data in direct marketing, and we do not provide personal data to anyone else for use in their direct marketing. Part VIA of the Ordinance (sections 35A to 35M) sets out the rules. Section 35C requires us to tell you what we intend to do and to obtain your consent before we use your personal data in direct marketing, and section 35J requires your written consent before we provide your personal data to anyone else for use in their direct marketing. If we ever intend to use your personal data in direct marketing, we will tell you which kinds of data and which classes of goods and services are involved, and we will ask for your consent first. You may withdraw that consent at any time by writing to the address in section 12.
5. Transfer and disclosure
We transfer or disclose personal data only in these situations:
- Service providers. Organisations that help us run the business, such as hosting, IT, accounting, and legal providers. They are bound by contract to protect the data and to use it only to provide their services to us.
- Legal requirement. Government bodies, courts, regulators, or other parties, where the law or a valid legal process requires disclosure.
- Font provider. Google receives the technical data your browser sends when a page loads fonts, as described in section 2.
- At your direction. When you ask us to disclose data, or agree that we may.
- Protection. Where we believe in good faith that disclosure is needed to protect the rights, property, or safety of Sweet Intelligence Limited, our clients, or others, or to investigate fraud or a security incident.
- A successor. A buyer or successor entity, if we are involved in a merger, acquisition, or sale of all or part of our business. We will require it to handle the data consistently with this policy.
We do not sell personal data.
6. Accuracy and retention
We take practicable steps to keep personal data accurate and up to date for the purpose it is used for, as DPP2 requires. Tell us if something we hold about you is wrong. We will correct it where we are satisfied that the data is inaccurate, and section 8 explains what happens if we are not.
We keep personal data only as long as it is needed for the purpose it was collected for, plus a reasonable period afterwards for legal, tax, and audit needs. Server logs are kept briefly. Once data is no longer needed, we delete or anonymise it.
7. Security
We apply reasonable technical and organisational safeguards to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use, as DPP4 requires. These include access controls, encryption in transit, and confidentiality obligations on our team and on our providers. No system is perfectly secure. We work to keep the impact of any incident as small as possible, and we will notify the people affected and the Privacy Commissioner where that is appropriate.
8. Your access and correction rights
Under DPP6 and sections 18, 22, and 23 of the Ordinance, a data subject may:
- Ask whether we hold personal data about you, and ask for a copy of that data.
- Ask us to correct personal data that is inaccurate.
Write to the address in section 12, say which request you are making, and give us enough information to identify the data and to confirm your identity. We use identity information for that purpose alone. Someone you authorise in writing may make a request on your behalf.
We respond within 40 days of receiving your request, as sections 19 and 23 of the Ordinance require. If we cannot comply in full within that period, we will write to you before it ends, give our reasons, comply so far as we are able, and complete our response as soon as practicable afterwards. Section 28 allows us to impose a fee for complying with a data access request. Any fee must not be excessive and will cover only the costs directly related to and necessary for complying with your request. We will tell you the amount before we proceed, and we do not charge for a data correction request. If we refuse a request, in whole or in part, we will explain the reason in writing. If you are not satisfied with how we handle your personal data or your request, you may complain to the Office of the Privacy Commissioner for Personal Data (PCPD).
9. Children
The Site is intended for business users and adults. We do not seek personal data from children. If you believe a child has sent us personal data, write to the address in section 12 and we will delete it.
10. Data processed outside Hong Kong
Some of our service providers process or store personal data outside Hong Kong. Where they do, we remain responsible for that data under DPP2 and DPP4, and we use contractual safeguards to hold each provider to comparable retention limits and security measures.
11. Changes to this policy
We may update this policy from time to time. The effective date at the top reflects the current version. We will flag material changes at the top of this page. Where a change would involve using personal data we already hold for a new purpose, we will seek your consent first.
12. Contact
Send questions about this policy, or a data access or correction request, by post to Sweet Intelligence Limited, Attn: the Privacy Compliance Officer, Flat/Rm 2108B, Champion Tower, Three Garden Road, Central, Hong Kong. Post is the channel we use for privacy matters, so please mark your letter clearly.
Making a request. Section 8 sets out how to ask for access to, or correction of, the personal data we hold about you. Requests go by post to the address in section 12, and we reply within 40 days.