Legal · Privacy

Privacy Policy

Effective 1 October 2025 · Version 2.0

Our engineering work usually involves client source code, data extracts and access credentials rather than personal data about individuals. This page sets out how Sweet Intelligence Limited handles the personal data it does hold, under the Personal Data (Privacy) Ordinance (Cap. 486).

1. Who we are

This policy is issued by Sweet Intelligence Limited, a company incorporated in Hong Kong on 21 May 2025 under the Companies Ordinance (Cap. 622), company number 78185856, with its office at Flat/Rm 2108B, Champion Tower, Three Garden Road, Central, Hong Kong. In this policy, "we", "us", or "our" refers to this company, and "the Site" refers to sweetintelligence.tech.

We are the data user for personal data collected through the Site and through our application, system and agent development, research and technical consulting engagements. This policy follows the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles.

2. What we collect

We collect only what we need, by lawful and fair means, and we tell a data subject what we are collecting at the time we collect it. Supplying personal data to us is voluntary. If you choose not to supply the contact details or engagement materials we ask for, we may be unable to answer your enquiry or to deliver the services you have engaged us to provide. In practice that means:

The Site uses no analytics cookies, advertising pixels, or third-party tracking. If that changes, we will update this policy before the change takes effect.

3. Why we collect it

We collect personal data for these purposes:

We use personal data for those purposes and for purposes directly related to them. DPP3 requires the data subject's consent before personal data is used for a new purpose, so if a new purpose arises we will ask you first. Access inside the company is limited to people who need the data for their work.

4. Direct marketing

We do not use personal data in direct marketing, and we do not provide personal data to anyone else for use in their direct marketing. Part VIA of the Ordinance (sections 35A to 35M) sets out the rules. Section 35C requires us to tell you what we intend to do and to obtain your consent before we use your personal data in direct marketing, and section 35J requires your written consent before we provide your personal data to anyone else for use in their direct marketing. If we ever intend to use your personal data in direct marketing, we will tell you which kinds of data and which classes of goods and services are involved, and we will ask for your consent first. You may withdraw that consent at any time by writing to the address in section 12.

5. Transfer and disclosure

We transfer or disclose personal data only in these situations:

We do not sell personal data.

6. Accuracy and retention

We take practicable steps to keep personal data accurate and up to date for the purpose it is used for, as DPP2 requires. Tell us if something we hold about you is wrong. We will correct it where we are satisfied that the data is inaccurate, and section 8 explains what happens if we are not.

We keep personal data only as long as it is needed for the purpose it was collected for, plus a reasonable period afterwards for legal, tax, and audit needs. Server logs are kept briefly. Once data is no longer needed, we delete or anonymise it.

7. Security

We apply reasonable technical and organisational safeguards to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use, as DPP4 requires. These include access controls, encryption in transit, and confidentiality obligations on our team and on our providers. No system is perfectly secure. We work to keep the impact of any incident as small as possible, and we will notify the people affected and the Privacy Commissioner where that is appropriate.

8. Your access and correction rights

Under DPP6 and sections 18, 22, and 23 of the Ordinance, a data subject may:

Write to the address in section 12, say which request you are making, and give us enough information to identify the data and to confirm your identity. We use identity information for that purpose alone. Someone you authorise in writing may make a request on your behalf.

We respond within 40 days of receiving your request, as sections 19 and 23 of the Ordinance require. If we cannot comply in full within that period, we will write to you before it ends, give our reasons, comply so far as we are able, and complete our response as soon as practicable afterwards. Section 28 allows us to impose a fee for complying with a data access request. Any fee must not be excessive and will cover only the costs directly related to and necessary for complying with your request. We will tell you the amount before we proceed, and we do not charge for a data correction request. If we refuse a request, in whole or in part, we will explain the reason in writing. If you are not satisfied with how we handle your personal data or your request, you may complain to the Office of the Privacy Commissioner for Personal Data (PCPD).

9. Children

The Site is intended for business users and adults. We do not seek personal data from children. If you believe a child has sent us personal data, write to the address in section 12 and we will delete it.

10. Data processed outside Hong Kong

Some of our service providers process or store personal data outside Hong Kong. Where they do, we remain responsible for that data under DPP2 and DPP4, and we use contractual safeguards to hold each provider to comparable retention limits and security measures.

11. Changes to this policy

We may update this policy from time to time. The effective date at the top reflects the current version. We will flag material changes at the top of this page. Where a change would involve using personal data we already hold for a new purpose, we will seek your consent first.

12. Contact

Send questions about this policy, or a data access or correction request, by post to Sweet Intelligence Limited, Attn: the Privacy Compliance Officer, Flat/Rm 2108B, Champion Tower, Three Garden Road, Central, Hong Kong. Post is the channel we use for privacy matters, so please mark your letter clearly.

Making a request. Section 8 sets out how to ask for access to, or correction of, the personal data we hold about you. Requests go by post to the address in section 12, and we reply within 40 days.