// LEGAL.PRIVACY

Privacy Policy

Version 2026-07-16

Version 1.1 · Effective Date: 16 July 2026

This Privacy Policy is designed to address the compliance with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) Laws of Hong Kong (“PDPO”).

1. Who We Are

X-Barriers Limited ("X-Barriers", "Company", "we", "our", or "us") is a company incorporated in the Hong Kong Special Administrative Region. We are the data user, from time to time, responsible for the collection, using, retaining, storing, transfers, and/or processing of personal data relating to you ("User", "you", or "your") through our websites, applications, and services (collectively, the "Services"). This data is necessary for providing you with the Services. Failure to provide us with this data may result in us being unable to provide you with the Services. The personal data we hold may be used to comply with any disclosure and/or notifications that we are required to make by governmental and regulatory authorities under the applicable laws and regulations of Hong Kong or to our service providers and can be used by us in connection with the provision of Services to you.

By accessing or using our Services, or otherwise providing your personal data to us, you hereby acknowledge and agree that your personal data will be collected, used, retained, stored, transferred, and/or processed as described in this Privacy Policy.

This Privacy Policy has been prepared to assist you to understand your rights and obligations in relation to personal data, as such term is defined in the PDPO, and the manner in which X-Barriers may use it. You are advised to read the following carefully and consult your own independent legal advisor or the Privacy Commissioner for Personal Data (“PCPD”), where necessary.

This Privacy Policy does not apply to third-party websites, platforms, products, or services that are not operated or controlled by X-Barriers, even if they are linked to, interoperated or integrated with our Services. Those third parties have their own privacy practices, and you should carefully review their applicable privacy notices.

2. Personal Data We Collect

We may collect the following categories of personal data, depending on how you interact with us and the Services:

  • Contact details, identification information, and/or other similar contact data (e.g., full name, email address, telephone number, date of birth, company name, job, title, mailing address, and other contact details or identification information you choose to input);
  • Identity verification or due diligence information, where necessary for security, compliance, fraud prevention, or contractual reasons (including child privacy, consumer protection, recordkeeping, and online safety obligations);
  • If a User is identified as a minor who is under the legal age of 18 years old (the “Minor User”): (a) the Minor User’s name, username, and date of birth or age range; (b) the Minor User’s account and usage information; (c) content or information submitted through the Services; (d) technical information necessary to operate, secure, and improve the Services; and (e) any other information reasonably necessary to provide the Service to the Minor User in a lawful manner;
  • If a User is identified as a Minor User, in order to obtain, verify, and maintain parental consent for such Minor User, personal information about a parent or legal guarding including: (a) full name; (b) email address; (c) telephone number; (d) billing or payment verification information, if used as part of a parental consent method; (e) government-issued identification information, if used for age or identity verification and where permitted by applicable law; (f) relationship to the Minor User; (g) records of consent, authorization, preferences, and communications; and (h) any other information reasonably necessary to verify that valid parental or guardian consent has been obtained;
  • Technical and usage data (e.g., device type, browser type, IP address, URLs, operating system, usage logs, timestamps, error logs, session activity, and interaction data);
  • Communications (e.g., inquiries, feedback, support requests, responses, and records of correspondence with us);
  • Security and diagnostic data used to maintain and protect the Services;
  • Cookies and tracking information (please see Section 5); and
  • Any other information, contents, data, and/or materials you voluntarily provide to us.

3. How We Use Your Personal Data (Purposes)

We use your personal data for the following purposes:

  • To provide, operate, maintain, support, and/or secure our Services;
  • To generate personalised AI-powered reports and insights based on the information, contents, data, and/or materials you submit when accessing the Services;
  • To ensure parental consent is obtained for Minor Users;
  • To respond to enquiries, requests, and/or complaints, and provide customer support;
  • To improve, develop, and enhance our Services and User experience;
  • To personalize User experience and improve functionality, performance, safety, and accessibility;
  • To monitor usage, troubleshoot issues, and develop new products and features for or in connection with the Services;
  • To ensure the security and integrity of our Services;
  • To detect, investigate, and prevent fraud, abuse, security incidents, unauthorised access, and other harmful or illegal activity;
  • To comply with applicable laws, regulations, codes of practice, lawful request, court orders, and legal process;
  • To establish, exercise, or defend legal claims and enforce our terms, contracts, and policies;
  • To protect our business, personnel, Users, systems, and property;
  • To facilitate corporate transactions (e.g., mergers, acquisitions, financing, reorganizations, or sales of assets);
  • To send important updates about the Services (where permitted); and
  • Any other purposes directly related to or arising in connection with any of the above.

We will only use your personal data for the purposes stated above or for purposes that are directly related to them, unless we have obtained your consent or are otherwise permitted by law.

If we intend to use your personal data for a new purpose that is materially different from the purpose for which it was collected, we will take steps required by applicable laws and regulations before doing so.

4. AI and Automated Processing

We may use artificial intelligence (“AI”), machine learning, and/or other processing technologies to support our business operations and to provide the Services. This may include using automated tools to generate reports and/or insights. We do not use your personal data to train, fine-tune, or improve any AI or machine learning models without your explicit prior consent.

This processing is fully automated. We do not make automated decisions that produce legal or similarly significant effects concerning you based on your use of our Services. You are solely and fully responsible for independently reviewing, evaluating, correcting, and personalizing any content, response, summary, analysis, or outputs generated by AI or other automated tools through our Services (“AI Output”) before relying on or submitting it, and where applicable, obtaining independent advice from a qualified professional.

AI-Output may be inaccurate, incomplete, misleading, biased, offensive, unlawful, infringing, non-unique, or unsuitable or unfit for your intended use or specific circumstances and should not be relied on as the sole basis for any decision, including any legal, financial, employment, compliance, or other important decision.

AI-Outputs are provided for general informational and educational purposes only. They do not constitute any form of professional advice. You remain solely and fully responsible for evaluating the accuracy, completeness, and suitability of any AI-generated output before relying on it. We do not represent or warrant that any AI-generated content, response, summary, analysis, recommendation, or output is accurate, complete, reliable, non-infringing, or fit for any particular purpose.

Specific AI sub-processors used by individual products are listed in the relevant product-level privacy notices.

5. Cookies and Tracking Technologies

We use only strictly necessary cookies and local storage required for the Services to function (e.g. session state and authentication). These are set by default and cannot be disabled without affecting the functionality of our Services. For the avoidance of doubt, “strictly necessary cookies” means any cookies required for the operation, security, and core functionality of the Services.

We do not currently use analytics cookies, preference cookies, functional cookies, advertising or targeting cookies, third-party tracking pixels, or behavioral profiling technologies. If we introduce analytics or preference cookies in the future, they will only be set with your explicit, opt-in consent and this Privacy Policy will be updated accordingly.

You may manage, control, or disable cookies through your browser or device settings. However, if you block or disable strictly necessary cookies, some parts of the Services may not function properly.

6. Disclosure and Sharing of Personal Data

We do not sell your personal data to third parties.

We may share your personal data to the following categories of recipients, to the extent reasonably necessary for the purposes described in this Privacy Policy:

  • Our affiliates, subsidiaries, and related entities (as the case may be);
  • Service providers and contractors (e.g., hosting, analytics, email delivery, and payment processing);
  • AI model providers who process data solely to generate AI-Outputs on our behalf;
  • Professional advisers, including legal advisers, accountants, auditors, and consultants;
  • Persons acting on or for your behalf, including your legal advisers, accountants, auditors, consultants, authorized representatives or executors, administrators or personal representatives;
  • Government agencies and law enforcement bodies, including the Hong Kong Police Force (in particular, the Joint Force Intelligence Unit) or PCPD; and
  • Any other regulators, government authorities, law enforcement bodies, courts, tribunals, and other third parties of other competent jurisdiction where disclosure is required or permitted by applicable laws and regulations.

We will notify you and, where required, re-obtain your consent before engaging a new category of sub-processor that materially changes how your personal data is processed.

7. International Transfers of Personal Data

By agreeing to our terms and conditions, accessing, or using our Services, you acknowledge and understand that your personal data is transferred to and processed in countries outside Hong Kong. These include, but are not limited to:

  • Google LLC (United States): Processes your inputs via the Gemini API for document generation. This transfer is governed by Google's Data Processing Addendum, which incorporates Standard Contractual Clauses.
  • Lovable Cloud (Singapore): Hosts our application infrastructure and database. This transfer is governed by contractual data protection terms incorporating equivalent protections.

For Users in Hong Kong, transfers are made in accordance with Data Protection Principle 3 of the PDPO, ensuring the recipient is contractually bound to provide a comparable standard of protection.

We do not transfer your personal data to entities beyond those named above without appropriate safeguards or your prior consent where required.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specific retention periods include:

  • Account data: retained while your account is active and for up to 12 months after account closure;
  • Submitted content/materials and generated document jobs: retained for up to 90 calendar days, unless you choose to save it to your account;
  • Transactional email logs (e.g. delivery and verification records): retained for up to 90 calendar days;
  • Consent, security, generation, routing, reconciliation, and operational audit logs: retained according to their operational category, generally up to 12 months where not otherwise required, using hashed or non-reversible identifiers where possible;
  • Payment, invoice, credit note, tax, accounting, and payment-routing records: retained as required by applicable financial, tax, accounting, and company laws;
  • Parental consent records: retained only as long as necessary to verify consent and demonstrate compliance, then deleted or anonymised when no longer required;
  • Suppression and unsubscribe records: retained as necessary to honour opt-out, suppression, security, and compliance obligations;
  • Grievance and admin review records: retained until the matter is resolved, plus 12 months for audit purposes.

Product-specific privacy notices may set shorter retention periods, in which case those shorter periods take precedence for the relevant Service. When personal data is no longer required, we will take reasonably practicable steps to erase, anonymize, or securely destroy it (as the case may be). Where you request erasure through the My Data portal, records that must be retained for legal, tax, accounting, fraud-prevention, or audit reasons may be anonymised rather than deleted, so identifying details are replaced with an opaque token while statutory or aggregate fields remain.

9. Data Security

We take reasonable practicable steps to implement appropriate technical and organisational measures to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use. These measures may include:

  • Encryption of data in transit using current TLS standards;
  • Encryption of data at rest using AES-256 or equivalent;
  • Role-based and row-level access controls on our databases;
  • Server-side storage of API keys and secrets, never exposed to client devices;
  • Short-lived session tokens with automatic refresh and rotation to reduce the risk of session hijacking; and
  • Regular review and update of our security controls.

No method of transmission over the internet or method of electronic storage is completely safe and secure. Accordingly, while we take reasonable steps to protect personal data, we cannot, in any whatsoever manner or capacity, guarantee absolute security.

10. Your Rights under the PDPO

Under the PDPO, you have the right to:

  • Request access to the personal data we hold about you;
  • Request correction of any inaccurate personal data;
  • Be informed of our policies and practices in relation to personal data; and
  • Withdraw your consent to the processing of your personal data (where consent was previously given), subject to legal or contractual restrictions.

As a service commitment in addition to your statutory rights, you may also request a copy of the personal data you have provided to us in a structured, commonly used, and machine-readable format (such as JSON). We may charge a reasonable fee for complying with data access request to the extent permitted by the PDPO.

To exercise any of these rights, please contact us using the details in Section 16, or via the My Data portal. We aim to respond to data access requests within 30 calendar days, and in any event no later than the maximum 40 calendar days as required by the PDPO. You may also lodge a complaint with the PCPD if you believe your rights have been infringed. The PCPD is an independent body established to oversee and monitor the implementation of and compliance with the provisions of PDPO in Hong Kong.

11. No Direct Marketing

We will not use your personal data for direct marketing purposes without your explicit consent. We do not provide, disclose, transfer, or sell your personal data to any third party for that third party’s direct marketing purposes. If you have given consent, you may opt out at any time by following the unsubscribe instructions in our communications or by contacting us. If we intend to use your personal data for direct marketing in future, we will do so only in accordance with the applicable laws and regulations, including the PDPO, and only after providing any required notices and obtaining any required consent.

12. Minor User’s Personal Data

Our Services are not intended for Minor Users. We do not knowingly collect personal data from a minor without appropriate authorization where required. Where a Service requires age verification, we implement a verification step before any personal data is collected. If you believe we have collected personal data from a Minor User, please contact us immediately so we can take reasonable steps to investigate and address such issue.

A parent or legal guardian may, subject to the PDPO:

  • Review personal data collected from or about the Minor User;
  • Request correction of inaccurate personal data;
  • Request deletion of the Minor User’s personal data where appropriate;
  • Withdraw consent for future collection, use, or disclosure; and
  • Request that we stop further use of Minor User’s account or terminate the account.

If a parent or legal guardian withdraws consent, we may suspend or terminate the Minor User’s access to all or part of the Services and delete associated personal data as required or permitted by the PDPO.

13. Personal Data Breach Notification

In the event of a personal data breach, we will notify any relevant regulator or authority in Hong Kong, including the Office of the PCPD or Hong Kong Police Force (in particular the Joint Force Intelligence Unit), without undue delay, and within 72 hours of becoming aware of the breach where feasible. Where a breach is likely to result in significant harm to affected individuals, we will notify those individuals without unreasonable delay. We maintain internal records of breaches for audit purposes.

14. Grievances

If you have a complaint about how your personal data is handled, please submit a grievance by emailing futurrupt@x-barriers.com. We will acknowledge your grievance within 48 hours and aim to resolve it within 30 calendar days.

If your grievance is not resolved to your satisfaction, you have the right to escalate the matter to the Office of the PCPD in Hong Kong.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or our Services or legal requirements. This policy is versioned; the version number and effective date appear at the top of this page. Material changes will be notified at least 14 calendar days before taking effect via our website, in-app notice, or email. Your continued use of the Services after such changes constitutes acceptance of the updated Privacy Policy. The update version will take effect from the effective date specified in the revised Privacy Policy.

16. Contact Us

If you have any questions, concerns, or wish to exercise your rights under this Privacy Policy on behalf of yourself or a Minor User, please contact us at:

futurrupt@x-barriers.com

We aim to respond to your request as soon as possible, and in any event no later than the 40 calendar days maximum required by the PDPO.

If you are not satisfied with our response, you may contact the Office of the PCPD in Hong Kong.

17. Language

This Privacy Policy is prepared and made available in English language only.

If this Privacy Policy is translated into any other language for convenience or reference, the English version will prevail to the fullest extent permitted by applicable laws and regulations in the event of any inconsistency or conflict between the English version and the translated version.

18. Corporate Information

X-Barriers Limited is legally incorporated in Hong Kong.

Company Business Registration Number: 80307303.

Registered Office: Unit 1603, 16FL, The L. Plaza, 367-375 Queen’s Road Central, Sheung Wan, Hong Kong