S SapienAI
Echo Lexra Zerva Why SapienAI FAQ Contact
Get in touch

Privacy Policy

Version 1.0 · Effective 26 August 2026

PART A — ABOUT THIS POLICY

1. Who we are

1.1 SapienAI (the operator of sapienevo.ai) ("SapienAI", "we", "our" or "us") provides practical AI products for professionals in Hong Kong, comprising Echo (the WhatsApp AI assistant), Lexra (medical document OCR) and Zerva (personal financial management), together with related services (the "Services"). Our contact details are set out in Section 24.

1.2 We respect the privacy of every individual whose personal data we handle, and we comply with the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of Hong Kong.

1.3 This Privacy Policy applies to our website at sapienevo.ai, to the Services, and to any service that incorporates this Policy. It does not apply to any service that has its own privacy policy which does not incorporate this one.

2. The two capacities in which we handle personal data

2.1 Where you visit our website, enquire about our products, register a tenant account, are billed by us, or receive communications from us, we decide why and how your personal data is used. In relation to that data we are the data user under the PDPO. Part B of this Policy explains what we do with it, and the rights you have against us.

2.2 Where a business uses our Services to record or process information about its customers, patients or clients — for example the WhatsApp messages handled by Echo, the medical documents processed by Lexra, or the financial records kept in Zerva — that business, not SapienAI, decides why and how that information is used. The business is the data user; we act as a data processor on its instructions, and we hold the information on its behalf. Part C of this Policy explains what that means, and whom an individual should approach to exercise their rights.

3. Definitions

In this Policy:

  • Anonymised Data — information which has been anonymised so that it no longer renders an individual identifiable, and with respect to which there is no reasonable basis to believe that it could be used to identify an individual.
  • End User — a customer, patient or client whose personal data is processed in the Services by a subscribed business.
  • Personal Data — as defined in the PDPO.
  • Tenant Content — the data processed in the Services by or for a subscribed business, including WhatsApp messages (Echo), uploaded documents (Lexra), and financial records (Zerva).
  • Subscribed Business — a clinic, pharmacy, agency or other organisation which subscribes to the Services.

PART B — WHERE WE ARE THE DATA USER

This Part applies to personal data about you, in your own right, as a visitor to our website, an enquirer, a tenant account holder, a billing contact, or a recipient of our communications.

4. What we collect

  • 4.1 Your name, professional role, organisation, email address, telephone number, postal address, and the content of enquiries and correspondence.
  • 4.2 The details used to register and operate a tenant account, including name, email address, telephone number, authentication credentials, role and permission settings, and account activity.
  • 4.3 Billing contact details, billing address, invoices and records of payments. Payment card details are collected and held solely by our payment processor; we do not receive or store your card number, expiry date or security code.
  • 4.4 Records of your contact with our support team, including correspondence and notes of telephone or messaging conversations.
  • 4.5 When you visit our website or use the Services, we may collect your IP address, browser type and version, operating system, referring page, pages viewed, approximate location, device information, and the dates and times of access.
  • 4.6 Where you choose to take part in a survey or in user research, the information you provide. Participation is always optional.
  • 4.7 We may receive information about you from your employer or organisation, from a colleague who invites you to join an account, or from our service providers.
  • 4.8 We do not directly collect from you information about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions or trade union membership, and we do not collect information about criminal convictions or offences. This Section concerns information we collect about you in your own right; it does not concern the clinical or client information that a business records using our software, which is dealt with in Part C.

5. Whether you must provide it

5.1 You are not obliged to provide personal data to us. However, if you do not provide the information necessary to register or operate an account, or to bill for the Services, we may be unable to provide those services to you or to the business you act for.

6. What we use it for

6.1 We use the personal data described in Section 4 for the following purposes:

  • (a) providing, maintaining, supporting and securing the Services; (b) creating, administering and authenticating accounts, and managing roles and permissions; (c) processing orders, issuing quotations and invoices, collecting payment, and maintaining accounting records; (d) responding to enquiries and providing customer support and training; (e) monitoring, analysing and improving the performance, reliability and security of our services, and developing new features; (f) detecting, investigating and preventing fraud, misuse, unauthorised access and breaches of our terms; (g) direct marketing, subject to Section 8; (h) complying with our legal and regulatory obligations, and establishing, exercising or defending legal claims; and (i) any other purpose you have consented to, or which is directly related to a purpose above.

6.2 We will not use your personal data for a new purpose that is unrelated to those above without first obtaining your consent.

7. Direct marketing

7.1 We may use your name, role, organisation, email address and telephone number to send you information about the Services, new products and features, events, training, offers, and news about SapienAI.

7.2 We will not use your personal data in direct marketing unless you have consented, or have indicated that you do not object. Where we ask for your consent we will tell you the kinds of personal data to be used and the classes of services to be marketed, and we will give you a channel through which to respond.

7.3 You may tell us at any time to stop using your personal data for direct marketing. We will do so without charge, and we will not require you to give a reason. You may opt out by using the unsubscribe link in any marketing message, or by writing to us at the address in Section 24.

7.4 We do not sell, rent or otherwise provide your personal data to any third party for that party's own direct marketing, whether for gain or otherwise.

7.5 Even if you opt out of direct marketing, we may still contact you about the services you have ordered, requested or enquired about, including service announcements, security notices, billing correspondence, changes to our terms, and support responses. These are not direct marketing and you cannot opt out of them while you hold an account.

7.6 We do not use Tenant Content, including End User data, for direct marketing of any kind, and we do not market to End Users. Where a Subscribed Business sends appointment reminders or other messages to its own customers through our software, the business is the sender and is responsible for that communication.

8. Cookies and analytics

8.1 Our marketing website uses only essential cookies (for example language preference and a secure session token for the portal). We do not use third-party advertising trackers on this site. Where analytics data is capable of identifying you, we treat it as personal data under this Policy.

9. Who we disclose it to

9.1 We may disclose the personal data described in Section 4 to the following classes of person:

  • (a) our employees and contractors, on a need-to-know basis; (b) our service providers, including hosting, AI model providers, communications, payment and support providers, under contracts that restrict their use of the data to providing those services; (c) the Subscribed Business you act for, in relation to your use of its account; (d) our professional advisers, including lawyers, accountants, auditors and insurers; (e) a purchaser or prospective purchaser of our business or assets, subject to appropriate confidentiality obligations; (f) regulators, law enforcement agencies, courts and tribunals, where required by law or by an order of a court or tribunal of competent jurisdiction; and (g) any other person with your consent.

9.2 We do not disclose personal data to any person for that person's own purposes except as described above.

10. Transfers outside Hong Kong

10.1 Where any personal data is transferred outside Hong Kong — for example to an AI model provider — we ensure that it is subject to protections comparable to those required by the PDPO, and we implement the Privacy Commissioner's recommended model contractual clauses where appropriate. Where we engage an AI model provider, we configure the processing so that your data is not used to train models shared with other customers.

10.2 This Policy is written by reference to the PDPO and does not address the requirements of the data protection regimes of other jurisdictions.

11. How long we keep it

11.1 We keep personal data only for as long as is necessary for the purposes described in Section 6, and in any event no longer than the following periods:

  • Enquiries which do not become customers: not more than 24 months from last contact.
  • Tenant account records: duration of the account, plus 24 months.
  • Billing and accounting records: 7 years.
  • Support correspondence: 7 years.
  • Website and usage logs: 12 months.
  • Marketing preferences and opt-out records: for as long as necessary to give effect to the opt-out.

11.2 We may keep personal data for longer where we are required to do so by law, or where it is necessary for the establishment, exercise or defence of legal claims. Personal data may persist in routine backups after it has been deleted from our live systems; backups are retained on a rolling basis for thirty-five (35) days and are then overwritten.

12. How we protect it

12.1 We take practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. Our measures include access controls, encryption of data in transit (TLS) and at rest, tenant-scoped data isolation, logging of user actions, personnel screening and training, and vulnerability and patch management.

12.2 No system can be guaranteed to be completely secure. In the event of a security breach affecting personal data, we will notify you as soon as practicable and tell you what information is at risk, the steps we have taken to protect it, and what we are doing to rectify the breach.

13. Your rights

  • 13.1 You may ask us whether we hold personal data about you, and ask for a copy of it.
  • 13.2 You may ask us to correct personal data about you which is inaccurate or incomplete.
  • 13.3 You may ask us to delete personal data about you, unless we are required to retain it by law or it is necessary for the establishment, exercise or defence of legal claims.
  • 13.4 You may ask us to provide personal data which you have given to us, or to transmit it to another person you nominate, in a structured, commonly used and machine-readable format.
  • 13.5 You may object at any time to the use of your personal data for direct marketing, and we will stop without charge and without asking your reasons.
  • 13.6 Where we rely on your consent, you may withdraw it at any time.
  • 13.7 Requests should be made in writing to the contact in Section 24. We may ask you to provide proof of identity and, where a request is made on your behalf, proof of authorisation. We will respond within thirty (30) calendar days. We may charge a fee for complying with a data access request, which will not be excessive.
  • 13.8 If your request concerns a record held by a Subscribed Business in our software, we will not be able to deal with it — Section 19 explains what to do instead.

14. Complaints

14.1 If you are concerned about how we have handled your personal data, please contact us first, using the details in Section 24, so that we have an opportunity to put it right.

14.2 You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, whose details are published at www.pcpd.org.hk.

PART C — WHERE WE ARE A DATA PROCESSOR

This Part concerns Tenant Content: the records that businesses keep about their customers, patients and clients using our Services — including WhatsApp messages (Echo), medical documents (Lexra) and financial records (Zerva).

15. Who decides what happens to the records

15.1 The Subscribed Business is the data user in respect of the Tenant Content it records in the Services. It decides what information is collected, for what purposes it is used, how long it is kept, and to whom it is disclosed.

15.2 SapienAI is a data processor. We hold and process Tenant Content on the instructions of the Subscribed Business and for the purpose of providing the Services — for example, processing WhatsApp messages so that Echo can reply, extracting document data so that Lexra can return structured output, and storing financial records so that Zerva can manage them.

15.3 A Subscribed Business is responsible for ensuring that its own agreements, privacy policies and collection statements permit Tenant Content to be provided to SapienAI and processed as described in this Policy, and for obtaining and maintaining any consent required.

16. What we do, and do not do, with Tenant Content

16.1 We host, store, transmit, back up, retrieve and display Tenant Content in order to provide the Services; we secure and monitor it; we assist businesses with support requests; and, where instructed, we migrate or export it.

16.2 We do not use Tenant Content for our own purposes. We do not sell it. We do not use it for direct marketing. We do not disclose it to any third party except as instructed by the Subscribed Business, as described in this Policy, or where required by law or by an order of a court or tribunal of competent jurisdiction.

16.3 Our personnel access Tenant Content only where necessary to provide, support or secure the Services, and are bound by confidentiality obligations.

17. Aggregated and anonymised data, and AI model training

17.1 We create aggregated and anonymised data derived from use of the Services. Before data is used in this way it is stripped of personal data, and it is prepared so that it cannot reasonably be used, alone or together with other information reasonably available to us, to identify any individual, business or organisation.

17.2 We use that aggregated and anonymised data to operate, secure, benchmark, evaluate and improve the Services, to develop new features, and for the training, validation and improvement of machine learning and artificial intelligence models. We do not use identifiable Tenant Content — such as the text of WhatsApp messages, the content of uploaded documents, or client records — to train shared models, and we configure our AI providers accordingly.

17.3 A Subscribed Business may tell us not to use data derived from its use of the Services for the training, validation or improvement of machine learning or artificial intelligence models. The request must be made in writing to the email address in Section 24. We will confirm in writing when the opt-out has taken effect, which will be within thirty (30) days of our receiving the request.

17.4 An opt-out operates from the date it takes effect. We are not able to reverse the training of a model that has already taken place, and an opt-out does not require us to retrain or delete an existing model. An opt-out is free of charge and does not affect the functionality available to the business.

17.5 SapienAI does not claim ownership of, and does not sell, license or otherwise commercialise, any dataset derived from Tenant Content.

18. If you are a customer, patient or client of a business that uses our Services

18.1 Your record — whether your WhatsApp conversation, your medical document, or your client profile — belongs to the business that treats or serves you, not to SapienAI. That business is responsible for it.

18.2 If you wish to see your record, ask for it to be corrected, ask how long it is kept, withdraw a consent you have given, or complain about how it has been handled, please contact the business directly. We are not permitted to give you access to a record held by a business, and we cannot correct it.

18.3 If you contact us about a record held by a business, we will tell you to approach the business, and we may notify the business that a request has been made. We will not disclose the content of any record to you.

18.4 To request the deletion of your data, please see our Data Deletion Instructions.

19. Retention, export and deletion of Tenant Content

19.1 We retain Tenant Content for as long as the Subscribed Business's subscription continues.

19.2 After a subscription is suspended or ends, functionality enabling the business to export its Tenant Content remains available for a period. After that period we delete or irreversibly de-identify it, except where we are required by law to retain it, where it is necessary for the establishment, exercise or defence of legal claims, or where it remains in routine backups which are overwritten in the ordinary course.

19.3 A business is responsible for exporting and retaining the records it is required to keep under the laws and professional obligations applicable to it.

PART D — GENERAL

20. Changes to this Policy

20.1 We may amend this Policy. We will publish the amended version with its version number and effective date, and where an amendment is material we will give at least thirty (30) days' notice.

20.2 We will not use personal data already collected for a materially different purpose without first obtaining consent where the PDPO requires it.

21. How to contact us

21.1 Requests, opt-outs and complaints under this Policy should be addressed to our Privacy Officer, using the details below.

SapienAI

Email: [email protected] · WhatsApp / Tel: +852 9164 1388

22. Related documents

22.1 This Policy should be read with our Terms of Service, where they apply. Where we act as a data processor, our obligations to the Subscribed Business are set out in our terms of service.

Version 1.0 · Effective 26 August 2026

S SapienAI

Practical AI for professionals. Made in Hong Kong.

Products
Echo Lexra Zerva
Company
About Contact Privacy Policy Terms of Service Data Deletion
Get in touch
[email protected] +852 9164 1388

© SapienAI. All rights reserved.