BUILDSYNC LIMITED · Hong Kong
Privacy Policy
Version: 2026-10-01-v1 · Effective date:
Contact address: Hong Kong Science and Technology Park
[email protected]
1. Who we are and our role
BUILDSYNC LIMITED is registered in Hong Kong. Contact address: Hong Kong Science and Technology Park. Privacy enquiries: [email protected]. We operate the public BuildSync website and Workspace. We determine the purposes of account administration, business communications, security and business records. For personal data in customer project material processed solely on customer instructions, the customer normally determines the purpose and we act as its processor under the relevant agreement. A customer's own notice also applies to project participants.
2. Information collected
We receive sign-in identity, name, email and profile image where provided; organisation and membership information; invitations and permissions; project documents, drawings, models, images, messages, extracted text, source references, AI inputs and outputs, and related metadata; enquiries and support messages; and necessary access, device, IP address and security-log information. Commercial records arise where a paid service is agreed. The public website does not provide general access to private Workspace material. Do not provide unrelated personal information, credentials or sensitive records. Other people's data must be supplied with appropriate authority and notices.
3. Purposes, necessity and choices
Relevant information is used to authenticate users, manage access, deliver instructed document/AI processing and collaboration, preserve project records, answer enquiries, administer contracts, secure the service, investigate incidents and meet legal obligations. Required account information is needed to operate an account; optional connection and preference information is voluntary. Declining a connection affects that functionality. Marketing requires its own applicable notice and choice; accepting service terms does not authorise unrelated marketing or model training.
4. AI, OCR and connections
Enabled AI/OCR providers receive task-relevant text, images or document portions and limited context. Processing records and outputs may form part of project history. Inference is different from training. Google sign-in requests identity information; Drive access requires a separate authorisation. Connecting or disconnecting a source is different from deleting previously imported material. Our Provider Information page identifies integrated services. Before submitting restricted material, request the applicable provider, processing-location and contractual information. We do not promise universal zero retention, no training or exclusive Hong Kong residency across third-party services. General model training or unrelated datasets using customer content require separate specific authorisation and a lawful basis; these terms alone do not grant it.
5. Recipients
Data is available to authorised project/workspace participants within their permissions and necessary operations/support personnel. Contracted hosting, storage, authentication, AI/OCR and communications providers receive information needed for their functions. Google Cloud hosting is in Singapore; optional external providers can process internationally. See Provider Information for purposes and service-specific details. Information may also be disclosed to advisers or competent authorities where law requires it or proportionate protection of legal rights or serious-harm prevention requires it. No general licence is granted to sell or publish private project content. A business transfer must preserve applicable confidentiality/privacy safeguards and notices.
6. International processing
Data may be processed outside Hong Kong, including Singapore hosting and international support or third-party processing. A cloud region is not proof that every log, backup or provider operation stays there. Appropriate contractual and other safeguards must be applied under the applicable law and agreement; UK transfers, where UK law applies, require the relevant adequacy or approved transfer arrangements and assessments. Contact us for the processing details and safeguards relevant to your service, subject to lawful confidentiality limits.
7. Cookies and tracking
We use necessary sign-in/security technologies and expressly selected language/theme preferences. This release does not embed Google Tag Manager, advertising tags or optional analytics tags in either the public website or Workspace. See the Cookies Notice. Future optional tracking requires its own applicable notice, consent or valid exemption and required objection mechanism before activation. Service acceptance and optional tracking choices are separate.
8. Retention and deletion
Account and project records are retained while needed for the service and applicable customer instructions. Security/support records are kept only as needed for protection, investigation and support; legal, accounting and dispute records may require longer retention. We assess purpose, sensitivity, contract and legal requirements instead of promising one universal period. Request service-specific periods through the privacy contact or agreement. Archive and soft-delete are not permanent erasure. Deletion may involve derived material, provider copies and backups; backup expiry and legal holds can delay final erasure. We will explain applicable limitations rather than claim every copy disappears immediately.
9. Security
We use access controls and operational safeguards appropriate to the information and service. Users must protect accounts, assign permissions carefully and report suspected unauthorised access. No system is risk-free. This notice does not claim independent certifications, complete vulnerability coverage or immunity from breaches. Confidential security reports belong with [email protected], not a public issue or project forum.
10. Access, correction and complaints
Contact [email protected] for access/correction requests, privacy questions or complaints. We may verify identity and authority and protect other people's information. Hong Kong data-access requests are generally handled within 40 calendar days, subject to applicable exceptions and lawful fees. Deletion, objection and other rights depend on applicable law; Hong Kong law does not create an unrestricted general erasure right. For customer-controlled material we will assist or refer to the responsible customer as appropriate. You may complain to the relevant regulator, including Hong Kong's Privacy Commissioner.
11. Children and overseas markets
BuildSync is intended for professional/business use, not a service directed at children. Our initial customer market is Hong Kong. Overseas use can trigger additional mandatory laws; contractual choice of Hong Kong law does not remove those rights. Contact us before deploying the service for a new jurisdiction or specially regulated data.
12. Updates
We publish the effective date and version. Material changes require appropriate notice and any necessary fresh choice. They do not retrospectively authorise unrelated processing. Relevant customer orders and data-processing agreements also govern processing within their scope.
