Privacy Policy
Last updated: 1 May 2025
This English version is provided for convenience. The traditional Chinese version remains the authoritative legal document; in case of discrepancy, the Chinese version prevails.
1. Overview & commitment
Keeonz Limited ("the Company", "we") values your personal privacy. This Privacy Policy ("Policy") explains how we collect, use, store, disclose and protect your personal data when you use the Man Yuen DSE application ("the App"). This Policy is drafted in accordance with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 553) ("the Ordinance") and its six Data Protection Principles, to ensure that our handling of your personal data fully complies with legal requirements. Please read this Policy carefully before using the App. By continuing to use the App, you agree to the handling of your personal data as described in this Policy. If you do not agree to the terms of this Policy, please discontinue use of the App.
2. Personal data we collect
We collect the following categories of personal data: [Account Data] • Email address (for account registration and identity verification) • Username or display name • Gender (optional) • DSE examination year (optional) [Usage & Learning Data] • Answer records and scores for practice questions • Completion status and scores for tests, exams and exercises • Learning progress and points records • Psychological test responses and results • AI advisor conversation content (questions and replies) [Device & Technical Data] • Device type and operating system version (automatically collected by the app framework) • App version • App usage frequency and feature usage patterns [Guest Data] • AI advisor usage count (tracked via anonymous counter, not linked to any personal account) We do not actively collect the following sensitive personal data: Hong Kong Identity Card numbers, financial data, biometric data, or medical/health data.
3. How we collect
We collect your personal data through the following means: (i) Account registration: when you register an account, we collect the email address and other personal data you provide. (ii) Optional profile completion: personal data you voluntarily enter on the profile settings page, such as gender and DSE year. (iii) Automatic collection during use: the system automatically records your usage data, including answer records and learning progress, as you use the App's features. (iv) AI advisor conversations: when you chat with the AI advisor, conversation content is transmitted to our AI service provider for processing in order to generate a response. (v) Psychological tests: when you complete a psychological test, your responses and results are recorded.
4. Purposes of use
We use your personal data for the following purposes (as applicable): (i) Providing and improving the Services 1. Service delivery: providing the App's services and user experience, including practice questions, learning guidance and associated features; 2. Personalised learning support: delivering personalised learning experiences, practice suggestions and content recommendations based on your usage and inputs; 3. Learning data management and results display: tracking, calculating and displaying your learning progress, answer performance, scores and related statistics; 4. Account management and support: managing and maintaining your account (if applicable), responding to enquiries, handling technical support requests and customer service matters; 5. Service stability: detecting, analysing and addressing issues arising from operational or system errors to maintain normal service operation. (ii) AI Advisor Service (Man Yuen Shu Tong) 1. Processing data to generate responses: transmitting your conversation messages and inputs (including but not limited to prompts, questions and context, depending on service design) to an AI language model to generate replies (see section 5); 2. Maintaining conversation context: processing your inputs and conversation context to ensure coherent responses aligned with your learning queries; 3. Improving AI response quality: subject to privacy and compliance requirements, conducting necessary quality control, error correction and model performance optimisation (e.g. content appropriateness checks and safety filtering, depending on system design). (iii) Psychological Test Service 1. Recording and displaying results: recording and displaying your test results, scores and associated explanations (depending on service design); 2. Providing historical records: displaying or managing your test history when you use your account or relevant features; 3. Ensuring test process operation: managing the test flow, input validation and necessary security checks. (iv) Security, Fraud Prevention and Risk Management 1. Preventing unauthorised access: detecting, preventing and addressing unauthorised logins, misuse or breaches of system security; 2. Fraud and abuse prevention: identifying, investigating and stopping fraudulent activity, malicious operations, cheating, or any conduct that may affect service fairness and security; 3. Internal risk control: conducting necessary security monitoring, log management and system inspection to reduce risk and maintain service reliability. (v) Analytics and Service Optimisation 1. Anonymous statistical analysis: using anonymous or de-identified statistics to analyse usage patterns, traffic sources and feature performance; 2. Improving content and features: optimising question banks, teaching presentation, test experience, system performance and overall product quality based on analysis results; 3. Performance and troubleshooting: detecting, assessing and improving service latency, error rates and other technical performance issues. (vi) Communications 1. Service-related notifications: sending you notifications directly related to service delivery, such as account/feature updates, important system changes, usage alerts, necessary notices and support messages; 2. Important announcements and compliance notices: notifying you of important matters when required by law or service operation.
5. Disclosure and third parties
We do not sell or rent your personal data. We may share data only with: (a) cloud database / authentication providers under strict contractual safeguards; (b) AI language-model providers, where we contractually require them not to use your conversations to train their models or for any purpose unrelated to providing the Services; (c) regulators or law enforcement where legally required, disclosing only the minimum necessary; (d) successors in a corporate transaction; and (e) trusted technical service providers bound by confidentiality.
6. Retention
Account data: for the life of the account plus up to three years. Learning records & psychological test results: for the life of the account. Anonymous statistics: may be retained indefinitely. On account termination we delete or anonymise identifiable data within a reasonable period (typically 60 working days), except where law requires retention.
7. Security
We use HTTPS/TLS in transit, secure cloud databases with access controls, hashed passwords, and regular security reviews. No transmission or storage is 100% secure; in the event of a data security incident we will act and notify affected users in line with the PDPO.
8. Your rights under the PDPO
You have the right to access (s.18) and correct (s.22) the personal data we hold about you, to opt out of direct marketing (we will obtain explicit consent before any such use), and to request deletion of your account and associated personal data. To exercise these rights, email cs@keeonz.ai with the subject "Data request". We will respond within 40 working days.
9. Children and minors
The App is designed for HKDSE candidates (typically aged 15 to 18). We recognise the importance of protecting minors' personal data privacy and take reasonable measures to mitigate data risks for minors. 1. Not for children under 13 The App is not designed for, promoted to, or intended to knowingly collect personal data from children under the age of 13. 2. Report unauthorised use immediately If a parent or guardian discovers that a minor has used the App without authorisation, please notify us via our designated contact channel. We will take reasonable and appropriate follow-up measures upon receiving such notification (including but not limited to restricting account features or reviewing data processing practices). 3. Inadvertent collection of data from children under 13 will be deleted If we become aware that we have inadvertently or inappropriately collected personal data from a child under the age of 13, we will delete or cease processing such data as soon as reasonably practicable, and assess whether remedial measures are needed to prevent recurrence. 4. Recommended guidance for minors If you are a minor, we recommend using the App under parental or guardian supervision. In particular when using the AI advisor, appropriate parental guidance is advised. Minors should avoid providing personally identifiable information (such as full name, phone number, address or other sensitive details) in conversations or submitted content, to reduce the risk of data leakage or misuse. 5. Possible restriction measures upon reasonable suspicion If we have reasonable grounds to suspect that a user may be under the age of 13, we may suspend some or all features, request additional information, or require verification to ensure use of the App complies with this Policy and reasonable privacy protection requirements.
10. Changes to this Policy
We may update this Policy from time to time. Updates take effect upon publication. Continued use of the Services after an update constitutes acceptance of the updated Policy.
11. Contact us
For any questions about this Policy, email cs@keeonz.ai with the subject "Privacy inquiry". Keeonz Limited Email: cs@keeonz.ai