Legal

Privacy Policy

Version: 1.0 (Beta)
Last updated: 5 August 2026
Data user / controller-processor roles: Mentalok (Hong Kong) Limited, trading as "Fidalab" ("Fidalab", "we", "us"), registered office DW 543-18, Unit 501-518, 5/F, Building 19W, No. 19 Science Park West Avenue, Hong Kong Science Park, Pak Shek Kok, New Territories, Hong Kong.

1. The two kinds of data we handle

We handle personal data in two distinct roles, and your rights differ between them:

(a) Account data — we act as data user (controller). Data about you as our customer: name, business email, organisation, login credentials, billing details (when paid plans launch), and usage records. We decide how and why this is processed.

(b) Document data — we act as processor on your instructions. Documents you upload, and prompts you submit to the askAI drafting feature, may contain personal data of third parties (names of contracting parties, signatories, contact details). For this data, you are the data user/controller and we process it solely to deliver the analysis and drafting you request, under the Data Processing Agreement ("DPA"). We do not use document data for any purpose of our own.

2. What we collect

  • You provide: account registration details; documents you upload; prompts you submit to askAI; support correspondence; feedback. Your name, business email, and organisation are required to create an account — without them we cannot provide the Service; all other information you choose to provide is voluntary.
  • Collected automatically: log data (IP address, browser type, timestamps, pages viewed), device information, and cookies necessary for authentication and security. We do not use advertising cookies during beta.
  • We do not collect: personal data from children; special/sensitive category data intentionally. Do not upload documents containing health, biometric, or similar sensitive data unless you have a lawful basis to do so.

3. Purposes of processing

We process personal data to: (a) provide, secure, and maintain the Service; (b) perform the document analysis and draft generation you request, including re-analysis of your stored documents when our analysis capability is updated or at your request; (c) communicate with you about the Service, including beta feedback; (d) comply with legal obligations; (e) establish or defend legal claims. We do not sell personal data, we do not share it with any third party for that third party's sales, marketing, or advertising purposes, and we do not use your documents, prompts, or their contents to train machine-learning models.

Where the European Union General Data Protection Regulation ("GDPR") applies, our legal bases are: performance of contract (Art. 6(1)(b)) for (a)-(b); legitimate interests (Art. 6(1)(f)) for security, product improvement using aggregated non-identifying data, and (e); legal obligation (Art. 6(1)(c)) for (d).

We do not use your personal data for direct marketing. If that ever changes, we will first inform you and obtain the consent required by Part 6A of the Personal Data (Privacy) Ordinance ("PDPO"), and you will be able to opt out at any time, free of charge.

4. How we store and analyse your documents

Secure storage. When you upload a document, it is transmitted encrypted (Transport Layer Security (TLS)) and stored encrypted at rest in access-controlled infrastructure operated by our database and storage sub-processor. Your workspace's data is logically separated from other customers' data, and every request to the Service is scoped to your workspace. Temporary copies created during upload are deleted automatically once processing completes. Your documents remain stored for as long as your account is active, so that they can be re-analysed as our analysis capability improves, or at your request. You can delete any uploaded document at any time; when you do, the document and the data derived from it are deleted.

Analysis. Each time a document is analysed: (1) relevant content is transmitted securely from storage to our AI sub-processor; (2) the AI sub-processor is contractually prohibited from using that content to train its models, and retains it only for a limited period for trust-and-safety (abuse) monitoring, in accordance with the provider's data-processing terms — the fact that we store your documents does not mean the AI provider keeps them; (3) the analysis results are returned to your account.

askAI. When you use askAI, your prompt (and any document context you include) is transmitted to the same AI sub-processor under the same no-training, limited-retention contractual terms. The generated draft is stored in your account until you delete it or close your account.

Extracted results (entities, obligations, alerts) remain in your account until you delete them or close your account.

5. Who we share data with

Only with sub-processors necessary to run the Service, each bound by contract to confidentiality, purpose limitation, and security obligations. These are: a database and storage provider (Singapore); an AI provider for document analysis and draft generation (United States — no model training; content retained only for a limited period for abuse monitoring, in accordance with the provider's data-processing terms); a hosting provider (Singapore — temporary upload copies deleted after processing); an authentication provider (United States — account data only); a payment processor (United States — account data only, when paid plans launch); and an email delivery provider (United States — service emails such as deadline reminders and account notices).

The current named list of sub-processors is maintained at https://www.fidalab.io/legal/sub-processors and forms the authoritative list; we will notify account holders before material changes. We never provide your documents or their contents to any third party for that party's sales, marketing, or advertising purposes.

We may also disclose personal data where required by law, court order, or regulatory authority, or in connection with a corporate transaction (with continuity of protection).

6. Retention

  • Uploaded documents: for the life of your account, or until you delete them — whichever is earlier.
  • askAI prompts and generated drafts: for the life of your account, or until you delete them.
  • Extracted results: for the life of your account, or until you delete them.
  • Account data: for the life of your account plus 7 years for records required by law (e.g. tax and accounting).
  • Logs: 90 days unless needed for security investigation.
  • Support correspondence and feedback: for as long as relevant to the enquiry or the beta programme; reviewed annually.

During beta, data may also be reset or deleted on reasonable notice as described in Clause 2.3 of the Terms.

When retention ends, data is deleted or irreversibly anonymised. Deletion extends to data derived from deleted documents. Deleted data may persist in encrypted backups until those backups expire in the ordinary course; backup copies are not accessed or restored except for disaster recovery, and remain protected until they expire.

7. Cross-border transfers

Our sub-processors process data outside Hong Kong, including in Singapore and the United States. We take steps to ensure transferred data receives protection comparable to the PDPO through contractual safeguards with each sub-processor. For personal data subject to the GDPR, transfers will be made under the European Commission's Standard Contractual Clauses or another valid transfer mechanism, put in place before any such data is processed.

8. Security

Measures include: encryption in transit (TLS) and at rest; logical separation of each customer workspace's data; role-based access on a need-to-know basis; and vendor due diligence on all sub-processors. Our infrastructure sub-processors hold independent security certifications such as Service Organization Control (SOC) 2 Type II and ISO/IEC 27001; these certifications are held by the sub-processors, and details are available via the sub-processor list at https://www.fidalab.io/legal/sub-processors. No system is perfectly secure. In the event of a data breach affecting your personal data, we will notify affected users without undue delay; for significant breaches we will also notify the Office of the Privacy Commissioner for Personal Data ("PCPD") in line with its recommended practice, and, where the GDPR applies, the competent supervisory authority within 72 hours.

9. Your rights

Under the PDPO you may request access to and correction of your personal data. We may charge a reasonable fee for access requests as permitted by the PDPO.

In addition, we voluntarily extend to all users: deletion of your account and associated data; a machine-readable export of your extracted results; and withdrawal from non-essential communications at any time.

Where the GDPR applies, users additionally have rights to erasure, restriction, portability, objection, and to lodge a complaint with a supervisory authority. These take effect automatically by operation of law.

Third-party data in documents: if your personal data appears in a document uploaded by one of our customers, the customer is the data user/controller; please direct requests to them. We will assist the customer in fulfilling such requests as their processor.

To exercise any right, contact info@mentalok.io. We respond to access and correction requests within 40 days as required by the PDPO (or within one month where the GDPR applies). Account deletion is completed within 30 days as set out in the DPA.

10. Cookies

We use strictly necessary cookies for login sessions and security. If we introduce analytics cookies, this policy and the cookie notice will be updated first.

11. Changes

We may update this policy from time to time. Material changes will be notified by email or in-app notice before they take effect.

12. Contact

Data privacy contact: info@mentalok.io, Mentalok (Hong Kong) Limited, trading as Fidalab, DW 543-18, Unit 501-518, 5/F, Building 19W, No. 19 Science Park West Avenue, Hong Kong Science Park, Pak Shek Kok, New Territories, Hong Kong.

If you are not satisfied with our response, you may complain to the PCPD (Hong Kong): https://www.pcpd.org.hk

Back to home