Privacy
Privacy Policy
This notice explains what personal data aiioy.io collects, why we collect it, who we share it with, and the rights you have over it under the Personal Data (Privacy) Ordinance of Hong Kong.
Who we are
Aiioy Technology Limited operates aiioy.io and is the data user responsible for the personal data described here.
Write to the Data Protection Officer, Aiioy Technology Limited, Rm 1508, 15/F, Office Tower Two, Grand Plaza, 625 Nathan Road, Mong Kok, Hong Kong, or email officials@aiioy.io. That is the address for any access or correction request.
What we collect
Described by category rather than field by field, so this stays accurate as the forms change.
- Enquiry forms — your name and email address, which we need in order to reply, plus your company name and industry if you choose to give them, and whatever you write in the message.
- Free AI development programme — the application at aiioy.io/100 collects your contact details (including your WhatsApp number), your company details and website, your role and experience, and a description of the work you want built. That description covers how your team works today, the systems and records you use, the problem you are trying to solve, who and how many people would use the result, the form and design you would like, and any reference sites — together with your IP address, browser identifier and how you reached the page.
- Automatically — our servers and analytics record the pages you visit, the site or advertisement you arrived from, your approximate location, and your browser and device type.
Personal data about other people
The application asks open questions about your operations, and answers sometimes contain names or contact details of your customers, staff or suppliers. Please leave those out where you can. If you do include them, you confirm you are entitled to pass them to us, and we will handle them under this notice.
Why we use it
We use enquiry data to answer you, and application data to assess whether we can build what you have asked for, to build it, and to contact you about it.
We use the automatic data to understand which pages are read, to keep the site secure and working, and to measure whether our advertising reaches the right people. We do not use it to make automated decisions about you.
Direct marketing
We do not use your phone number or email address to send you promotional messages you did not ask for. If that ever changes we will ask for your consent first, separately, and you will be able to opt out at any time.
The newsletter is the one exception, and only if you signed up for it. Every issue carries a way to unsubscribe.
Who we share it with
We do not sell personal data, and we do not share it for anyone else’s marketing. We use these classes of service provider, and each one only receives what it needs to do its job.
- Form relay and email — FormSubmit carries enquiry forms to our mailbox, and the message then sits in our own email service like any other correspondence.
- Hosting and infrastructure — Cloudflare serves the site, protects it from attack, provides cookieless visitor statistics, and holds the programme application records in its database service.
- Meta Platforms — receives the advertising measurement described below if you accept it, and also carries the WhatsApp conversation that follows an application, including your phone number and what you write there.
- AI service providers — we send only what is needed to design and build your prototype, under confidentiality and security terms.
- Professional advisers and authorities — where we are required to disclose by law, or need advice on a legal claim.
Showing our work
Before we show any project publicly we remove or anonymise personal data and non-public business information. If a case study could still identify a person or a client, or would reveal non-public business information, we ask for your explicit written agreement first — separately from the programme terms.
Saying no does not affect your application or what we deliver to you.
Cookies and advertising measurement
We ask before any advertising cookie is set. Until you accept, this site does not contact Meta at all, and declining leaves the site fully usable. You can change your answer at any time through the "Cookie settings" link in the footer.
If you accept, the Meta pixel reports to Meta when a page is viewed, when an enquiry form is submitted successfully, and when a WhatsApp link is clicked, together with your IP address and a cookie identifier. Meta uses this to measure our advertising and to build audiences we can advertise to.
We have not enabled Meta’s automatic advanced matching, so the pixel is not configured to send Meta the name or email address you type into our forms.
The application pages at aiioy.io/100 and aiioy.io/100/go carry the same Meta pixel as the rest of this site, under the same consent choice: until you accept, those pages do not contact Meta either. Cloudflare’s visitor statistics use no cookies and do not identify you.
How long we keep it
Enquiry emails are kept while we are in contact with you about the enquiry, and for up to 24 months afterwards so we can pick up a conversation you return to.
Applications to the free development programme are kept for the duration of the programme and for up to 24 months after it closes. Server and advertising logs follow the retention periods of Cloudflare and Meta respectively.
Your rights
Under the Personal Data (Privacy) Ordinance you may ask us whether we hold personal data about you, ask for a copy of it, and ask us to correct it if it is wrong. Write to the Data Protection Officer at the address above. We will reply within 40 days, as the Ordinance requires. We may need to confirm your identity first, and a reasonable fee may apply to a copy request.
Separately from those rights, you can tell us at any time to stop contacting you, and we will.
The Ordinance does not give a general right to erasure. As a matter of practice, if you ask us to delete your data and we have no legal or contractual reason to keep it, we will.
Security and where your data goes
The site is served over HTTPS and application records are held in an access-controlled database. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Our service providers operate globally, so your data may be processed on servers outside Hong Kong. We only use providers that commit to protecting it.
If something goes wrong
If personal data is lost or exposed we will investigate, take what steps we can to limit the damage, and record what happened. Where the incident is likely to cause real harm we will notify the people affected and, where appropriate, the Privacy Commissioner for Personal Data.
Changes
If we change how we handle personal data we will update this page and change the date below. Material changes will be highlighted here.
Last updated: 11 August 2026
