Privacy Policy

Registered office: 21st Floor, The Phoenix Building, 23 Luard Road, Wan Chai, Hong Kong S.A.R.
Effective date: 18 May 2026
Last updated: 18 May 2026
privacy@insyteful.ai
Hong Kong S.A.R.

1. About us and this policy

Insyteful Limited (“Insyteful”, “we”, “us”, “our”) is a Hong Kong–incorporated learning technology company. We provide an AI‑powered learning platform for small and mid‑sized organisations across the Asia‑Pacific region.We take privacy seriously. This policy explains how we collect, use, share, and protect personal data — under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”), the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and other applicable data protection laws.For privacy matters, contact us at privacy@insyteful.ai or by post at the address above.

2. Who this policy applies to

This policy describes how we handle personal data of:

For platform learner data processed under a customer subscription, Insyteful acts as a data processor on behalf of the customer organisation, which is the data controller. A separate Data Processing Addendum between Insyteful and the customer governs that relationship. This policy applies to all other interactions.

3. What personal data we collect

3.1 Identity and contact data

Name, job title, organisation, work email, work phone, work address, professional profile links (e.g. LinkedIn).

3.2 Account data

Login credentials, account preferences, language and time‑zone settings, role and permissions within your organisation's account.

3.3 Learner data (platform users)

Courses enrolled, completed, time spent learning, assessment results, skill profiles, certificates earned, learning path progress, manager feedback, and other records of platform activity.

3.4 Billing and transaction data

For customer organisations: company billing details, purchase order references, invoices. Payment card details are handled by our payment processor (Stripe) and are not stored by Insyteful.

3.5 Communications data

Records of correspondence with us (email, chat, support tickets, meetings), survey responses, feedback, and call notes.

3.6 Marketing and engagement data

Marketing preferences, email open and click activity, event attendance, content downloads, webinar registrations.

3.7 Website and device data

IP address, browser type, device identifiers, pages viewed, referring URL, time and duration of visits, and similar technical data. Cookies and similar technologies are described in Section 9.

3.8 Recruitment data

For applicants: CV, cover letter, work history, references, right‑to‑work documentation, interview notes, assessment results.

3.9 Sensitive data

We do not knowingly collect sensitive personal data (such as data revealing racial or ethnic origin, religious beliefs, health data, or biometric data). If sensitive data is required for a specific purpose (e.g. accessibility accommodations), we will collect it only with your explicit consent and a clear lawful basis.

4. How we collect personal data

5. Why we use personal data and our legal basis

The table below sets out our processing purposes, the lawful basis we rely on under GDPR, and the corresponding basis under PDPO.

Purpose

Operating, securing, and improving our website

Marketing our products to business contacts

Providing the platform under a customer subscription

Customer administration, billing, and account management

Learner record-keeping and reporting to the employer / sponsor

Customer support and service communications

Generating aggregated and anonymised analytics

Recruitment and hiring

Detecting and preventing fraud, abuse, and security incidents

Complying with legal, tax, audit, and regulatory obligations

Defending or pursuing legal claims

Lawful basis (GDPR)

Legitimate interest

Legitimate interest (B2B); consent where required

Performance of contract

Performance of contract; legal obligation

Performance of contract (with the customer)

Performance of contract; legitimate interest

Legitimate interest

Pre-contractual steps; legitimate interest

Legitimate interest; legal obligation

Legal obligation

Legitimate interest

PDPO basis

Directly related to operating our online presence

Direct marketing with opt-out (PDPO s.35)

Contractual purpose

Contractual and statutory purpose

Disclosed purpose under PDPO Principle 1

Directly related purpose

Permitted use of anonymised data

Disclosed purpose

Directly related purpose

Statutory purpose

Permitted use

When we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. When we rely on legitimate interests, we have assessed that those interests are not overridden by your privacy rights, and you can object at any time.

6. Who we share personal data with

We share personal data only with the following categories of recipients, and only as needed:

6.1 Service providers acting on our behalf

All processors are bound by written contracts requiring them to process personal data only on our instructions and to apply appropriate security measures.

6.2 Customer organisations

For learners using the platform under an employer subscription, we share learner records (e.g. course completions, assessment results, compliance evidence) with that customer organisation. The customer is the data controller for that learner data.

6.3 Professional advisors

Lawyers, accountants, auditors, tax advisors, and corporate service providers retained by Insyteful.

6.4 Government, regulators, and law enforcement

Where required by law, court order, or lawful regulatory request, including the Hong Kong Inland Revenue Department, the Hong Kong Companies Registry, and relevant financial‑services or data‑protection regulators.

6.5 Successors in a business transaction

If Insyteful is involved in a merger, acquisition, financing, restructuring, or sale of all or part of its business, personal data may be transferred to the relevant counterparty or successor entity, subject to confidentiality and continued protection.

6.6 With your consent

We share personal data with any other third party only with your specific, informed consent.

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.

7. International transfers of personal data

Insyteful is based in Hong Kong. Our service providers are located in Hong Kong, Singapore, other Asia‑Pacific jurisdictions, the European Union, the United Kingdom, and the United States.
Where we transfer personal data across borders, we rely on appropriate safeguards, including:

You can request more information about the safeguards in place for specific transfers by emailing privacy@insyteful.ai.

8. How long we keep personal data

We retain personal data only for as long as necessary for the purposes set out in this policy.

Category

Website server logs

Marketing prospect data

Marketing opt-out and suppression records

Customer account records

Learner records held on behalf of a customer

Compliance and certification records

Communications and support records

Recruitment records (unsuccessful applicants)

Recruitment records (successful applicants)

Supplier and partner records

Typical retention period

12 months

Duration of active interest, then up to 24 months after last engagement, unless you opt out earlier

Indefinite (so we can honour your opt-out)

Duration of the subscription, plus 7 years (Hong Kong accounting and tax retention)

As instructed by the customer in the Data Processing Addendum

As required by the applicable regulator or framework, typically 5–7 years

3 years after closure of the relevant ticket or matter

12 months from close of role, unless you ask us to retain for future opportunities

Duration of employment, plus 7 years

Duration of the relationship, plus 7 years

At the end of the retention period, we securely delete or fully anonymise the data.

9. Cookies and similar technologies

Our website uses:

We do not currently use advertising or cross‑site tracking cookies. You can manage non‑essential cookies through our cookie banner and your browser settings.
A separate Cookie Notice sets out the specific cookies in use, their purpose, and their duration.

10. Your rights

Subject to applicable law, you have the right to:

To exercise any of these rights, email privacy@insyteful.ai. We will respond within 30 calendar days. We may ask you to verify your identity before acting on a request.
If you are dissatisfied with our response, you have the right to complain to:

11. How we protect personal data

We use appropriate technical and organisational security measures, including:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals within statutory timeframes (72 hours under GDPR; without undue delay under PDPO).

12. Children

Insyteful's services are designed for business use by professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have collected data from a minor, please contact us and we will delete it.

13. Third‑party websites and services

Our website and platform may contain links to, or integrate with, third‑party websites and services. This policy does not apply to those services. We encourage you to read the privacy policies of any third party before providing personal data to them.

14. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, services, or legal requirements. Material changes will be communicated through the website and, where appropriate, by direct notice to active customers. The “Last updated” date at the top of this policy shows when it was last revised. We encourage you to review this policy periodically.

15. Contact

Privacy queries and rights requests: privacy@insyteful.ai

Postal address:

Privacy Officer

Insyteful Limited

21st Floor, The Phoenix Building23 Luard RoadWan ChaiHong Kong S.A.R.