Version 1.0 · Effective 26 August 2026
1.1 SapienAI (the operator of sapienevo.ai) ("SapienAI", "we", "our" or "us") provides practical AI products for professionals in Hong Kong, comprising Echo (the WhatsApp AI assistant), Lexra (medical document OCR) and Zerva (personal financial management), together with related services (the "Services"). Our contact details are set out in Section 24.
1.2 We respect the privacy of every individual whose personal data we handle, and we comply with the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of Hong Kong.
1.3 This Privacy Policy applies to our website at sapienevo.ai, to the Services, and to any service that incorporates this Policy. It does not apply to any service that has its own privacy policy which does not incorporate this one.
2.1 Where you visit our website, enquire about our products, register a tenant account, are billed by us, or receive communications from us, we decide why and how your personal data is used. In relation to that data we are the data user under the PDPO. Part B of this Policy explains what we do with it, and the rights you have against us.
2.2 Where a business uses our Services to record or process information about its customers, patients or clients — for example the WhatsApp messages handled by Echo, the medical documents processed by Lexra, or the financial records kept in Zerva — that business, not SapienAI, decides why and how that information is used. The business is the data user; we act as a data processor on its instructions, and we hold the information on its behalf. Part C of this Policy explains what that means, and whom an individual should approach to exercise their rights.
In this Policy:
This Part applies to personal data about you, in your own right, as a visitor to our website, an enquirer, a tenant account holder, a billing contact, or a recipient of our communications.
5.1 You are not obliged to provide personal data to us. However, if you do not provide the information necessary to register or operate an account, or to bill for the Services, we may be unable to provide those services to you or to the business you act for.
6.1 We use the personal data described in Section 4 for the following purposes:
6.2 We will not use your personal data for a new purpose that is unrelated to those above without first obtaining your consent.
7.1 We may use your name, role, organisation, email address and telephone number to send you information about the Services, new products and features, events, training, offers, and news about SapienAI.
7.2 We will not use your personal data in direct marketing unless you have consented, or have indicated that you do not object. Where we ask for your consent we will tell you the kinds of personal data to be used and the classes of services to be marketed, and we will give you a channel through which to respond.
7.3 You may tell us at any time to stop using your personal data for direct marketing. We will do so without charge, and we will not require you to give a reason. You may opt out by using the unsubscribe link in any marketing message, or by writing to us at the address in Section 24.
7.4 We do not sell, rent or otherwise provide your personal data to any third party for that party's own direct marketing, whether for gain or otherwise.
7.5 Even if you opt out of direct marketing, we may still contact you about the services you have ordered, requested or enquired about, including service announcements, security notices, billing correspondence, changes to our terms, and support responses. These are not direct marketing and you cannot opt out of them while you hold an account.
7.6 We do not use Tenant Content, including End User data, for direct marketing of any kind, and we do not market to End Users. Where a Subscribed Business sends appointment reminders or other messages to its own customers through our software, the business is the sender and is responsible for that communication.
8.1 Our marketing website uses only essential cookies (for example language preference and a secure session token for the portal). We do not use third-party advertising trackers on this site. Where analytics data is capable of identifying you, we treat it as personal data under this Policy.
9.1 We may disclose the personal data described in Section 4 to the following classes of person:
9.2 We do not disclose personal data to any person for that person's own purposes except as described above.
10.1 Where any personal data is transferred outside Hong Kong — for example to an AI model provider — we ensure that it is subject to protections comparable to those required by the PDPO, and we implement the Privacy Commissioner's recommended model contractual clauses where appropriate. Where we engage an AI model provider, we configure the processing so that your data is not used to train models shared with other customers.
10.2 This Policy is written by reference to the PDPO and does not address the requirements of the data protection regimes of other jurisdictions.
11.1 We keep personal data only for as long as is necessary for the purposes described in Section 6, and in any event no longer than the following periods:
11.2 We may keep personal data for longer where we are required to do so by law, or where it is necessary for the establishment, exercise or defence of legal claims. Personal data may persist in routine backups after it has been deleted from our live systems; backups are retained on a rolling basis for thirty-five (35) days and are then overwritten.
12.1 We take practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. Our measures include access controls, encryption of data in transit (TLS) and at rest, tenant-scoped data isolation, logging of user actions, personnel screening and training, and vulnerability and patch management.
12.2 No system can be guaranteed to be completely secure. In the event of a security breach affecting personal data, we will notify you as soon as practicable and tell you what information is at risk, the steps we have taken to protect it, and what we are doing to rectify the breach.
14.1 If you are concerned about how we have handled your personal data, please contact us first, using the details in Section 24, so that we have an opportunity to put it right.
14.2 You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, whose details are published at www.pcpd.org.hk.
This Part concerns Tenant Content: the records that businesses keep about their customers, patients and clients using our Services — including WhatsApp messages (Echo), medical documents (Lexra) and financial records (Zerva).
15.1 The Subscribed Business is the data user in respect of the Tenant Content it records in the Services. It decides what information is collected, for what purposes it is used, how long it is kept, and to whom it is disclosed.
15.2 SapienAI is a data processor. We hold and process Tenant Content on the instructions of the Subscribed Business and for the purpose of providing the Services — for example, processing WhatsApp messages so that Echo can reply, extracting document data so that Lexra can return structured output, and storing financial records so that Zerva can manage them.
15.3 A Subscribed Business is responsible for ensuring that its own agreements, privacy policies and collection statements permit Tenant Content to be provided to SapienAI and processed as described in this Policy, and for obtaining and maintaining any consent required.
16.1 We host, store, transmit, back up, retrieve and display Tenant Content in order to provide the Services; we secure and monitor it; we assist businesses with support requests; and, where instructed, we migrate or export it.
16.2 We do not use Tenant Content for our own purposes. We do not sell it. We do not use it for direct marketing. We do not disclose it to any third party except as instructed by the Subscribed Business, as described in this Policy, or where required by law or by an order of a court or tribunal of competent jurisdiction.
16.3 Our personnel access Tenant Content only where necessary to provide, support or secure the Services, and are bound by confidentiality obligations.
17.1 We create aggregated and anonymised data derived from use of the Services. Before data is used in this way it is stripped of personal data, and it is prepared so that it cannot reasonably be used, alone or together with other information reasonably available to us, to identify any individual, business or organisation.
17.2 We use that aggregated and anonymised data to operate, secure, benchmark, evaluate and improve the Services, to develop new features, and for the training, validation and improvement of machine learning and artificial intelligence models. We do not use identifiable Tenant Content — such as the text of WhatsApp messages, the content of uploaded documents, or client records — to train shared models, and we configure our AI providers accordingly.
17.3 A Subscribed Business may tell us not to use data derived from its use of the Services for the training, validation or improvement of machine learning or artificial intelligence models. The request must be made in writing to the email address in Section 24. We will confirm in writing when the opt-out has taken effect, which will be within thirty (30) days of our receiving the request.
17.4 An opt-out operates from the date it takes effect. We are not able to reverse the training of a model that has already taken place, and an opt-out does not require us to retrain or delete an existing model. An opt-out is free of charge and does not affect the functionality available to the business.
17.5 SapienAI does not claim ownership of, and does not sell, license or otherwise commercialise, any dataset derived from Tenant Content.
18.1 Your record — whether your WhatsApp conversation, your medical document, or your client profile — belongs to the business that treats or serves you, not to SapienAI. That business is responsible for it.
18.2 If you wish to see your record, ask for it to be corrected, ask how long it is kept, withdraw a consent you have given, or complain about how it has been handled, please contact the business directly. We are not permitted to give you access to a record held by a business, and we cannot correct it.
18.3 If you contact us about a record held by a business, we will tell you to approach the business, and we may notify the business that a request has been made. We will not disclose the content of any record to you.
18.4 To request the deletion of your data, please see our Data Deletion Instructions.
19.1 We retain Tenant Content for as long as the Subscribed Business's subscription continues.
19.2 After a subscription is suspended or ends, functionality enabling the business to export its Tenant Content remains available for a period. After that period we delete or irreversibly de-identify it, except where we are required by law to retain it, where it is necessary for the establishment, exercise or defence of legal claims, or where it remains in routine backups which are overwritten in the ordinary course.
19.3 A business is responsible for exporting and retaining the records it is required to keep under the laws and professional obligations applicable to it.
20.1 We may amend this Policy. We will publish the amended version with its version number and effective date, and where an amendment is material we will give at least thirty (30) days' notice.
20.2 We will not use personal data already collected for a materially different purpose without first obtaining consent where the PDPO requires it.
21.1 Requests, opt-outs and complaints under this Policy should be addressed to our Privacy Officer, using the details below.
Email: [email protected] · WhatsApp / Tel: +852 9164 1388
22.1 This Policy should be read with our Terms of Service, where they apply. Where we act as a data processor, our obligations to the Subscribed Business are set out in our terms of service.
Version 1.0 · Effective 26 August 2026