Privacy Policy
AequiLex ("we", "us", "our") operates this service and is the data controller for your personal information. This Privacy Policy explains how we collect, use, disclose, and protect your personal data in compliance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO"). By using our service, you agree to the practices described in this policy.
1. Data Collection & Storage
We collect and store both personal data (data that identifies you) and non-personal data (data that does not identify you):
Personal Data we store:
- Authentication Data: Email address, user ID, and authentication tokens from OAuth Provider.
- Payment Data: Credit card details and transaction history (if you subscribe to a paid plan).
Non-Personal Data we store:
- Conversations: Your legal research queries, AI-generated responses, and conversation titles (unless you include identifying information about yourself or others in your queries).
- Usage Analytics: Token counts, query volumes, system performance metrics.
- Local Storage & Cookies: Your browser's localStorage is used to maintain authentication sessions. The authentication system may set essential cookies as needed for proper functioning. Cookies are not intentionally used for tracking or analytics purposes, though third-party services may set their own necessary cookies.
2. Personal Information Collection Statement (PICS)
In accordance with Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486), we provide the following information about our collection of your personal data (data from which your identity can be ascertained):
- Purpose of Collection: Your personal data is collected for: (a) account creation and authentication, (b) providing access to the service, (c) processing payments and billing (if applicable), and (d) complying with legal obligations.
- Classes of Personal Data: We collect: email address, OAuth authentication tokens, user ID, and payment information (credit card details, transaction history - if you subscribe).
- Transfer of Personal Data: Your personal data will be transferred to: authentication service providers (for OAuth login), cloud infrastructure providers (for database hosting), and payment processors (if you subscribe). See "Cross-Border Data Transfers" section for details.
- Your Rights: You have the right to request access to and correction of your personal data. You may also request deletion of your data, subject to our legal retention obligations. Requests can be made to info@aequilex.io.
- Voluntary/Mandatory: Providing an email address for account creation is mandatory. Payment information is only required if you choose to subscribe to a paid plan.
- Consequences of Non-Provision: If you do not provide an email address, we will be unable to create your account or provide the service to you.
3. Non-Personal Data
The service also collects and processes data that is not personal data under the PDPO, as it does not directly or indirectly identify you:
- Legal research queries: Your questions and search terms (unless you include your own personal information in them).
- Conversation content: AI-generated responses and your research conversations (unless you include identifying information).
- Usage metrics: Token counts, query volumes, system performance data.
Non-personal data may be used for system improvement, analytics, and service optimization without the restrictions applicable to personal data under PDPO.
4. Personal Data (Privacy) Ordinance Compliance
This service complies with Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"). We collect and process personal data in accordance with the six Data Protection Principles:
- Purpose & Collection (DPP1): Personal data is collected for the lawful purpose of providing legal research services and is collected fairly with your knowledge through account creation and service usage.
- Accuracy & Retention (DPP2): We take practicable steps to ensure data accuracy and retain personal data only as long as necessary for service provision and legal obligations.
- Use of Data (DPP3): Personal data is used only for the purposes stated in our Personal Information Collection Statement or directly related purposes. You agree that data which is not Personal Data within the definition under PDPO may be used by the service provider to improve the system.
- Security (DPP4): We implement appropriate technical and organizational measures, such as Row Level Security in our database and restricted database access except only for technical tasks, to protect personal data against unauthorized access, processing, erasure, loss, or use.
- Information to be Generally Available (DPP5): We maintain transparent policies about our data handling practices.
- Access to Personal Data (DPP6): You have rights to access, correct, and object to processing of your personal data as detailed below.
5. Your Data Rights
Under the PDPO, you have the right to:
- Request access to your personal data held by us.
- Request correction of inaccurate personal data.
- Object to processing of your personal data.
- Request deletion of your personal data (subject to legal retention requirements).
- Receive reasons if any request is refused.
- Lodge a complaint with the Privacy Commissioner for Personal Data if you believe your rights have been violated.
6. Data Access & Correction Request Procedures
To exercise your right to access or correct your personal data, please submit a written request to info@aequilex.io with:
- Your full name and account email address.
- Specific details of the personal data you wish to access or correct.
- Proof of identity (copy of HKID card or passport).
- For correction requests, the proposed amendments and supporting documentation.
Processing Time: We will respond to your request within 40 days of receiving all necessary information and verification documents.
Fees: For data access requests, we may charge a reasonable fee not exceeding HK$200 to cover our administrative costs. Correction requests are generally processed free of charge. We will inform you of any applicable fees before processing your request.
Refusal: If we refuse a data access or correction request (wholly or partially), we will provide written reasons and inform you of your right to complain to the Privacy Commissioner.
7. Data Retention
We retain your data for the following periods:
- Active account data: Retained while your account is active.
- Conversations: Stored indefinitely unless you delete them manually.
- Deleted conversations: Permanently removed from our systems within 30 days.
- Account deletion: All personal data purged within 90 days of account deletion request.
- Usage logs: Retained for up to 12 months for system monitoring and debugging.
You can delete individual conversations or your entire account at any time through the account settings.
8. Cross-Border Data Transfers
In accordance with Section 33 of the PDPO, we inform you that your personal data will be transferred to jurisdictions outside Hong Kong for processing:
Authentication Service Providers (OAuth):
- Personal Data Classes Transferred: Email address, OAuth authentication tokens, user ID.
- Purpose: Account authentication and login services.
- Safeguards: Industry-standard OAuth 2.0 security, encryption in transit and at rest, contractual data protection obligations.
Cloud Infrastructure Providers (Cloudflare D1):
- Personal Data Classes Transferred: Email address, user ID, authentication tokens.
- Purpose: Database hosting and application infrastructure.
- Safeguards: SOC 2 Type 2 certified, AES-256 encryption at rest, TLS encryption in transit, row-level security policies, contractual data processing agreements.
Payment Processors (Stripe - if applicable):
- Personal Data Classes Transferred: Email address, payment information, transaction details.
- Purpose: Processing subscription payments.
- Safeguards: PCI-DSS Level 1 certified (highest security standard for payment processors), SOC 1/SOC 2 certified, encryption in transit and at rest, contractual data protection obligations.
Non-Personal Data Transfers: Your legal research queries and conversation content are processed by AI service providers including Google LLC (Gemini API), located in the United States and other jurisdictions. These are generally not personal data unless you include identifying information about yourself or others.
Your Consent: By using this service, you expressly consent to these cross-border transfers of personal data. You acknowledge that the data protection standards in these jurisdictions may differ from Hong Kong's requirements, but we ensure reasonable contractual and technical safeguards are in place.
Transfer Security: All transfers are conducted using encrypted channels (TLS/HTTPS). We require all third-party processors to implement appropriate security measures and use your data only for the purposes specified.
9. Security Measures
We implement commercially reasonable security measures to protect your personal data, including:
- Encryption of data in transit (HTTPS/TLS) and at rest.
- Row-level security policies in our database to isolate user data.
- Restricted database access limited to essential technical operations.
- Regular security assessments and monitoring for unauthorized access.
- Secure authentication through trusted OAuth providers.
However, no internet transmission is completely secure. While we strive to protect your data, we cannot guarantee absolute security. You acknowledge the inherent security risks of internet services.
10. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by Hong Kong law, typically within 72 hours of becoming aware of the breach. Notifications will include the nature of the breach, affected data, and steps we're taking to address it.
11. Direct Marketing
We currently do not use your personal data for direct marketing purposes. Should we wish to use your personal data (including your name and email address) for direct marketing of our services in the future:
- We will obtain your written consent before using your data for such purposes.
- You will be clearly informed of what data will be used and for which products/services.
- You can opt-out or withdraw consent at any time free of charge.
- We will not provide your data to third parties for their direct marketing without your separate consent.
If you receive any marketing communications from us that you did not consent to, please contact info@aequilex.io immediately.
12. Children's Privacy
This service is intended for use by legal professionals, researchers, and law students who are at least 18 years of age. We do not knowingly collect personal data from individuals under 18 years old.
If you are under 18, you must not use this service or provide any personal information to us. If we discover that we have inadvertently collected personal data from a person under 18, we will delete that information promptly.
13. Consent & Withdrawal
By creating an account and using this service, you provide your explicit consent to the collection, use, and processing of your personal data as described in this policy. For first-time users, you will be prompted to explicitly agree to these terms before accessing the service.
You may withdraw your consent at any time by contacting us or deleting your account, though this may limit your ability to use the service.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy.
- Notify you via email to your registered account email address.
- Display a prominent notice on the service homepage or within your account dashboard.
- For significant changes affecting your rights, we may require your explicit re-consent.
Your continued use of the service after notification of changes constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you should discontinue use and may delete your account.
15. Contact for Privacy Matters
For privacy-related inquiries, data access requests, or to exercise your rights under the PDPO, contact: info@aequilex.io