This privacy policy establishes how we process and
protect your personal information.
1. Commitment and Scope
LuDuan ("we", "us" or "our") is committed to complying with the provisions of the Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong) (the "Ordinance") and with the six Data Protection Principles that underpin it. This Privacy Policy Statement (this "Statement") explains, in plain terms, how we collect, use, retain, transfer, disclose and protect your personal data, and it describes the rights you can exercise over that data. It applies to every interaction you have with us, whether online or offline.
This Statement applies to the following categories of individuals:
- Visitors who browse our website (the "Platform"), including those who have not registered an account;
- Clients who register for and use our services ("Clients"), including account holders and authorised representatives of corporate clients;
- Individuals who submit service enquiries, corporate-plan requests or partnership applications to us, whether or not those enquiries convert into an engagement;
- Professionals who apply to become consultants on our Platform ("Consultants"), including applicants whose applications are declined, and individuals who provide referee or background-check information on a Consultant's behalf;
- Partners who apply to or participate in the LuDuan Marketing Partner Programme ("Partners"), including applicants whose applications are declined.
By using the Platform, submitting any personal data to us, or providing personal data about you to us through any channel (including email and the enquiry forms), you confirm that you have read and understood this Statement. If you provide us with personal data about any other individual (for example, a colleague who is the contact person for an engagement), you confirm that you are authorised to do so and that you have informed that individual of this Statement.
2. Categories of Personal Data We Collect
The personal data we collect depends on your relationship with us. The main categories are set out below, and we collect only data that is necessary for the purposes described in Section 3.
2.1 Client Data
If you are a Client, or you enquire about becoming one, we may collect and hold the following personal data:
- Your name, company name and job title, so that we know who you are and on whose behalf we are acting;
- Your contact details, including your email address and telephone number, so that we can communicate with you about enquiries, orders, deliverables and payment;
- Your account login credentials. Your password is stored only in encrypted form and cannot be read by our staff;
- Payment information. Where you pay by card, your card details are collected and processed directly by our third-party payment service providers (such as Stripe) and are not stored on our own systems beyond the transaction records they return to us;
- The service requirements, project details, files and any other documents or information you submit through the Platform in connection with your engagement, because these are necessary for us and the assigned Consultant to perform the service;
- Correspondence between you, us and the Consultants assigned to your engagements, including support requests and revision instructions, so that we have an accurate record of what was agreed and delivered.
2.2 Consultant Data
If you are a Consultant, or you apply to become one, we may collect and hold the following personal data:
- Your name, contact details, professional qualifications and certifications, so that we can assess and present your competence to clients accurately;
- Your work experience, areas of expertise and service history on the Platform, which we use to match you with suitable engagements;
- Identity documents and related information collected for background checks and compliance purposes, including any know-your-client or anti-fraud checks we are required to perform;
- Your bank account details or FPS proxy data, which are used solely to pay your service fees;
- Correspondence with us, client ratings of your work and internal performance reviews, which we use to maintain the quality and reputation of the consultant community.
2.3 Website Usage Data
When you access the Platform, our systems and service providers automatically record certain technical and usage data, including:
- Your IP address, browser type and version, and operating system, which are used to deliver the site correctly and to diagnose faults;
- Browsing history on the Platform, click behaviour and session duration, which help us understand which services and pages are useful to users;
- Data collected through cookies and similar tracking technologies, as described in Section 10 of this Statement.
2.4 Partner Data
If you are a Partner, or you apply to become one, we may collect and hold the following personal data:
- Your name and contact details, so that we can assess your application and communicate with you about the Programme;
- Your payout details, such as your bank account information or FPS proxy data, which are used solely to pay your commissions;
- Identity and verification information collected for anti-fraud and compliance purposes, where required;
- Records of your promotional activity and referrals made under the Programme, which are used to calculate commissions and administer participation;
- Correspondence with us regarding the Programme.
3. Purposes of Collection
We collect your personal data for the following purposes, and we will not use your personal data for any new purpose that is incompatible with these purposes unless we have obtained your prescribed consent or the use is otherwise permitted by the Ordinance.
3.1 Client-Related Purposes
- To process your service orders, assign them to appropriately qualified Consultants and deliver the resulting service deliverables to you;
- To communicate with you about your enquiries, orders, invoices, payment reminders and client support requests;
- To process payments, prevent payment fraud and issue invoices and receipts;
- To improve our service quality, personalise your experience and develop new services based on aggregated usage patterns;
- To comply with our legal, tax and regulatory obligations, including record-keeping requirements that apply to us as a service provider.
3.2 Consultant-Related Purposes
- To assess your application, verify your professional credentials and conduct the background checks described in Section 2.2;
- To match you with suitable client projects and to present your expertise to clients in a manner consistent with our service model;
- To manage your service assignments, calculate and pay your service fees, and administer client ratings and performance evaluations;
- To maintain the quality and reputation of the consultant community, including removing Consultants who repeatedly breach our standards.
3.3 Partner-Related Purposes
- To assess Partner applications, verify identity and eligibility, and administer participation in the LuDuan Marketing Partner Programme;
- To calculate, administer and pay commissions, and to detect and investigate fraud, self-referral or other abuse of the Programme;
- To comply with our legal, tax and record-keeping obligations in connection with the Programme.
3.4 General Purposes
- To maintain the security and proper operation of the Platform, including detecting, investigating and mitigating fraudulent, unlawful or abusive activity;
- To conduct data analysis and research to improve the user experience of the Platform;
- To conduct direct marketing to the extent permitted by law and only in accordance with Section 6 of this Statement;
- To fulfil our legal and regulatory obligations and to establish, exercise or defend our legal rights.
4. Artificial Intelligence and Automated Processing
Our core service model involves the use of artificial intelligence (AI) technology. Because this materially affects how your data is processed, we explain it in detail here rather than in general terms.
4.1 Role of AI in Processing Client Data
When we receive a service request and related materials from a Client, parts of the workflow are processed automatically by our AI systems. Depending on the service ordered, this may include:
- Preliminary analysis and categorisation of the materials you submit, so that the engagement can be scoped and assigned efficiently;
- Generation of draft service reports, assessment results or recommendations, which are then refined during the engagement;
- Identification of potential risks, gaps or compliance issues for closer human review;
- Provision of data-driven insights and suggestions that support the Consultant preparing your deliverable.
4.2 Legal Basis for AI Processing
Under Data Protection Principle 3 of the Ordinance, personal data must not be used for a new purpose that is incompatible with the purpose for which it was collected. We therefore commit to the following:
- All purposes for which AI processing is used are set out in Section 3 of this Statement, and our AI systems are operated only for those purposes;
- We will not use your client data to train, fine-tune or customise AI models unless we have obtained your explicit and voluntary consent in advance;
- If we intend in future to use client data for any new purpose, such as model training, we will seek your separate and prescribed consent beforehand, and you will be free to refuse without affecting your use of the Platform.
4.3 Collaboration Between AI and Human Review (HITL)
Our service model is "AI-driven + Human-in-the-Loop (HITL)". In practice this means:
- Our AI systems handle the majority of the initial automated processing work, which keeps our turnaround times and prices competitive;
- Every final deliverable is reviewed and validated by a qualified Consultant before it is sent to you;
- Your data may therefore be processed by our AI systems and accessed by the Consultants assigned to your engagement, subject to the access controls described in Section 5.1.
5. Transfer and Disclosure of Personal Data
We do not sell your personal data. We disclose it only in the circumstances described in this Section, and only to the extent necessary.
5.1 Disclosure to Consultants
To facilitate service delivery, we transfer a Client's service requirements and related materials to the Consultant assigned to the project. All Consultants have signed confidentiality agreements and are bound by the Platform's data protection policies. We protect the confidentiality of client data through the following measures:
- Tiered access rights: Consultants can only access data strictly necessary for their assigned tasks, and their access is limited to the Platform's own tooling;
- Data minimisation: only the minimum data required to complete the assigned task is transferred to the Consultant;
- Technical isolation: client data does not leave the Platform environment; Consultants work within the Platform rather than on local copies;
- Audit trails: data access is logged, and logs are monitored for unusual activity.
5.2 Disclosure to Third-Party Service Providers
We may transfer personal data to the following categories of third parties, each of which performs a function that is necessary to operating the Platform:
- Payment processing service providers (such as card gateways and banks), which handle payment authorisation and settlement and the payment of Marketing Partner Programme commissions;
- Cloud hosting and data storage providers, which host the Platform and its databases;
- Technical maintenance and support providers, which help us keep the Platform available and secure;
- Legal, accounting and compliance advisors, where their advice requires access to personal data.
All third-party service providers are engaged under contracts that require them to comply with data protection standards equivalent to those in this Statement, and they may process personal data only in accordance with our documented instructions.
5.3 Disclosure Required by Law
We may disclose your personal data where the disclosure is required by applicable law, by a court order, or by a lawful and binding request from a government, regulatory or law-enforcement authority. Where the law permits, we will notify you of any such request before disclosure and will disclose only the minimum data required.
5.4 Cross-Border Data Transfers
Our service providers may host or process data outside the Hong Kong Special Administrative Region. Where personal data is transferred outside Hong Kong, we will take all practicable steps to ensure that the transfer complies with the requirements of the Ordinance and that the recipient is bound by safeguards no less protective than those in this Statement, for example through contractual data-protection clauses.
6. Direct Marketing
We may use your personal data, including your name, contact details and records of the services you have enquired about or purchased, to send you information about our own services, promotions and events by email or other message channels.
6.1 Your Rights
Under Section 35C of the Ordinance, before we use your personal data for direct marketing we must, among other things:
- Inform you that we intend to use your personal data for direct marketing;
- Inform you of the categories of personal data to be used and the classes of services, products and subjects to be marketed;
- Obtain your explicit and voluntary consent, which you may give or withhold, and which you may withdraw at any time.
6.2 Right to Opt-Out
You have the right to request, at any time and free of charge, that we cease using your personal data for direct marketing. Every marketing message we send includes an unsubscribe mechanism, and you may also exercise this right by notifying us using the contact details in Section 12 below. Once we receive your request, we will stop using your personal data for direct marketing without charge and within a reasonable time.
7. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised or accidental access, processing, erasure, loss or use, having regard to the kind of data and the harm that could result. These measures include:
- Encryption of data in transit using SSL/TLS, so that data you submit cannot be read while travelling over the internet;
- Encryption of data at rest in our databases and file storage;
- Access controls and authentication mechanisms, including role-based permissions that limit what each team member and Consultant can see;
- Regular security reviews, vulnerability assessments and penetration testing of the Platform;
- Data-protection training and confidentiality obligations for our staff and Consultants.
No method of transmission or storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security, and we encourage you to use strong passwords and to keep your credentials confidential.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes set out in Section 3, including any period required by applicable law, tax and audit rules. When the data is no longer needed, it will be securely deleted or irreversibly anonymised. Our standard retention periods are:
- Client account data: for the duration of the account's activity and up to 7 years after closure, to meet legal and audit requirements;
- Service records and deliverables: up to 7 years after delivery of the engagement;
- Consultant data: for the duration of the consultant relationship and up to 7 years after it ends;
- Partner records: for the duration of participation in the Marketing Partner Programme and up to 7 years after it ends;
- Website usage data: up to 12 months, after which it is deleted or aggregated so that it no longer identifies you.
In some cases we may retain minimal data for longer where necessary to resolve disputes, enforce our agreements or comply with lawful retention obligations, and we will explain the reason if you ask us about a specific retention decision.
9. Your Rights
Under the Ordinance you have enforceable rights over the personal data we hold about you. We handle every rights request promptly, transparently and free of charge unless the law permits a reasonable fee.
9.1 Right of Access and Correction
You have the right to request access to the personal data we hold about you, which means obtaining a copy of that data, and to request correction of any personal data that is inaccurate or incomplete. For example, you may ask us for a copy of the contact details and order history associated with your account, or ask us to correct an out-of-date telephone number. We may charge a reasonable fee for processing an access request, and if we do we will tell you the amount before proceeding.
9.2 How to Exercise Your Rights
To access or correct your personal data, submit a written request to us using the contact details in Section 12 below. We may ask you for information sufficient to verify your identity before we act on the request, and we will respond within the time frame required by the Ordinance. If we refuse a request, we will explain the reason and, where applicable, how you can challenge that refusal.
9.3 Right to Complain
If you believe that we have breached the Ordinance in the way we handle your personal data, you may complain to us directly using the contact details in Section 12, and we will investigate and respond. You also have the right to complain to the Office of the Privacy Commissioner for Personal Data (PCPD) at any time.
10. Cookies and Tracking Technologies
We use cookies and similar technologies for the following purposes:
- Maintaining your login status and session so that you do not have to re-authenticate on every page;
- Recording your preferences, such as language and display choices;
- Analysing website traffic and usage patterns so that we can improve the Platform;
- Supporting the security of the Platform, for example by detecting unusual login behaviour.
You may refuse or delete cookies through your browser settings at any time. If you do so, parts of the Platform that depend on sessions, such as ordering and account management, may not function correctly.
11. Updates to This Privacy Policy Statement
We may update this Statement from time to time to reflect changes in our practices, our services or applicable law. The latest version will always be published on this page together with its revision date. Where the changes are material and your contact details allow, we will also notify you directly. By continuing to use the Platform after an updated Statement takes effect, you accept the updated Statement.
12. Contact Us
If you have any questions about this Statement or wish to exercise your rights of access, correction or opt-out of direct marketing, please contact us at:
Data Protection Officer
LuDuan
Email: ai@luduan.io
13. Governing Language
This Privacy Policy Statement is available in both English and Chinese. In the event of any inconsistency between the English and Chinese versions, the English version shall prevail.