Legal

Privacy Policy

How we collect, use, store and transfer personal data, under the Personal Data (Privacy) Ordinance (Cap. 486).

Last updated: 2 September 2026

This Privacy Policy explains how NextBoard Solutions Limited ("Aidisclose", "we", "us"), operator of the Aidisclose platform at app.aidisclose.ai (the "Service"), collects, uses, stores and transfers personal data, and the choices and rights you have. It is addressed to our clients' authorised users, client contacts, and visitors to our sites, and constitutes our Personal Information Collection Statement under the Personal Data (Privacy) Ordinance (Cap. 486) (the "PDPO").

1. Who is responsible for your data

For account, usage and site data described in §2, Aidisclose is the data user.

For personal data contained in matter content — documents, deal facts, chat and other material a client submits to the Service — the client is the data user, and we process that material on the client's behalf and instructions as a data processor under our Terms of Service. If your personal data appears in a client's matter content, the client is responsible for the lawful basis of its collection; requests concerning it should be addressed to the client, and we will assist the client in responding.

2. What we collect

We collect only what the Service needs:

  • Account data — name, work email address, organisation, role, and account identifiers. Accounts are provisioned by us on a client's nomination; we do not operate self-service sign-up. Passwords are stored only as salted cryptographic hashes; we cannot read them.
  • Usage and audit data — actions taken on the Service (sign-ins, views, uploads, job triggers, releases, downloads) with timestamps and the acting account, recorded on a tamper-evident audit trail; technical logs including IP address and browser type; credit/usage metering records.
  • Communications — messages you send us (e.g. support email), and, once notification email is enabled, delivery records for account emails such as password resets.
  • Matter content — processed for the client as described in §1; it may incidentally contain personal data (e.g. names of directors or counterparties in documents).

We do not collect biometric data, and the Service is not directed at minors.

3. Purposes of collection and use

We use personal data to:

1. provision, secure and operate accounts and the Service, including authentication, role-based access control and per-client isolation;
2. deliver the workflows a user triggers, including AI-assisted analysis and human review;
3. maintain the audit trail — a professional-records and security function: establishing who saw, edited, released or downloaded what, and when;
4. meter usage and administer fees and credit allowances;
5. communicate service, security and account matters;
6. comply with legal and regulatory obligations, and establish or defend legal claims;
7. improve the Service using aggregated, de-identified operational metrics only.

Supplying account data is voluntary, but without it we cannot provision or maintain an account. We will not use personal data for a new purpose without consent as required by the PDPO.

No model training. Neither matter content nor personal data is used to train or fine-tune AI models — by us, and contractually by our AI provider.

No direct marketing. We do not use personal data in direct marketing. If that ever changes, we will first seek consent in accordance with Part 6A of the PDPO, and you may opt out at any time without charge.

4. Who receives data (transferees and processors)

We do not sell personal data. Data is disclosed only to:

  • (a) AI inference provider — Anthropic (United States), directly or via Amazon Web Services' Bedrock service. Matter content (including uploaded document text and images and chat) is transmitted for processing to produce the requested analysis. It is not used to train models and is automatically deleted by the provider within 30 days — subject to narrow exceptions where content is flagged under the provider's safety and legal obligations.
  • (b) Hosting provider — Hostinger (data centre: Malaysia), which hosts the application, the database, document storage and backups.
  • (c) HKEX / HKEXnews (Hong Kong) — the Service retrieves public filings by stock code; the retrieval discloses to HKEX which issuer is being researched and when, but no matter content.
  • (d) Web-search providers (currently Brave Search and DuckDuckGo, United States) — in deep-research workflows the AI system composes web-search queries. Queries are recorded on the matter's audit trail and the system is instructed not to include confidential or personal details in them.
  • (e) Email provider — Amazon Web Services (Simple Email Service, United States), once account and notification email is enabled — recipient addresses and message content for account email only (no matter content).
  • (f) Professional advisers, and authorities where disclosure is required by law, regulation or court order, or necessary to establish or defend legal claims.

A current subprocessor list is available on request.

5. Retention

We keep personal data no longer than necessary for the purposes above:

  • Account data — for the life of the account and 12 months after deactivation.
  • Matter content — for the life of the matter and 12 months after closure, after which it is disposed of; a client may request earlier disposal of a matter, which removes its documents, artifacts and chat from the live system.
  • Audit trail — 7 years, reflecting professional-record and limitation-period practice. The audit trail records actions and metadata, not document content, and survives matter disposal.
  • Backups — backup copies of the database are kept on a rolling schedule (daily for 14 days, weekly for 8 weeks and monthly for 6 months) and are deleted no later than 200 days after creation. Backup copies of documents mirror the live store, so a document deleted from the platform drops out of the backup at the next nightly run.

Where data is held for us by the providers in §4, their deletion runs on the schedules stated there.

6. Security

The Service is built for pre-disclosure price-sensitive information, and its security measures protect personal data equally:

  • encryption in transit (HTTPS/TLS) for all access;
  • encryption at rest for uploaded documents, generated artifacts, job inputs and chat messages;
  • role-based access control with per-client and per-matter isolation; clients see only their own matters;
  • authentication with modern password hashing (argon2), minimum password strength, sign-in rate-limiting, and short-lived sessions;
  • an append-only, hash-chained audit trail of access and actions;
  • no client data in source control, and secrets held outside the codebase.

No system is perfectly secure. If we become aware of a data breach materially affecting personal data, we will notify affected clients without undue delay and notify the Office of the Privacy Commissioner for Personal Data where appropriate.

7. Cookies

The Service uses a single essential session cookie (httpOnly; Secure in production) to keep you signed in. We do not use advertising, analytics or cross-site tracking cookies, and the application serves its fonts and assets from our own domain — no third-party font or CDN request is made from authenticated pages.

8. Transfers outside Hong Kong

Personal data is transferred outside Hong Kong to the recipients in §4 — in particular AI inference in the United States and hosting in Malaysia. Section 33 of the PDPO (transfer restrictions) is not yet in operation; we nonetheless follow the Privacy Commissioner's recommended practice by transferring only under written terms that require the recipient to protect the data to standards comparable to the PDPO (including the no-training and retention terms in §4(a)).

9. Your rights

Under the PDPO you may:

  • request access to personal data we hold about you (a data access request under s.18); we may charge a fee limited to the cost of compliance and will respond within 40 days;
  • request correction of inaccurate personal data (s.22);
  • for matter content where the client is the data user (§1), we will pass your request to the client and assist it in responding.

Requests: info@nextboardsolutions.com, marked "Data Access/Correction Request". We may need to verify your identity before acting.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the Service or by email, with the "last updated" date above revised. Continued use after that date constitutes acceptance.

11. Contact

Data privacy contact: NextBoard Solutions Limited · info@nextboardsolutions.com

If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk).