SindalTechnology International

Legal

Privacy Policy

Sindal Technology International Limited (星德科技國際有限公司)
Effective date: 29 August 2026

This policy explains what personal data Sindal Technology International Limited (“Sindal”, “we”, “us”) collects, why we collect it, who we share it with, and what rights you have. It applies to this website, to GrowOS, and to any Sindal customer account used to subscribe to GrowOS.

We are the data user (data controller) for the personal data described here. Our registered office is:

Sindal Technology International Limited
Flat/Rm D, Blk 6, 1/F, The Paramount
23 Shan Tong Road, Tai Po
New Territories, Hong Kong

Privacy enquiries and data requests: [email protected]
General enquiries: [email protected]

1. What we collect

1.1 Account and organisation information

When you create a Sindal customer account or a GrowOS account we collect your name, email address, the password you choose (stored only as a cryptographic hash, never in readable form), your preferred language, and the details of the business you register — business name, industry, contact channels, opening hours and business address where you provide them. If you invite colleagues, we store their email address and their role within your organisation.

1.2 Content you give us

GrowOS works from materials you supply: photographs of your shop, your products and your work, your logo, brand information, and the written directions you give about what you want produced. We store these materials, the marketing content generated from them, and the record of the work — drafts, revisions, approvals and the conversation with your marketing assistant.

1.3 Facebook and Instagram data obtained with your authorisation

If you connect a Facebook Page or an Instagram professional account, we receive data from Meta only after you complete Meta's authorisation flow and grant the requested permissions. What we then receive and store is:

  • the identifiers, names and profile images of the Pages and Instagram accounts you connected, and the access tokens needed to act on them;
  • the posts published to those accounts through GrowOS, together with their publication status and identifiers;
  • comments and direct messages received on those accounts, including the sender's platform name and identifier and the content of the message, so that GrowOS can show them to you and reply on your behalf;
  • basic performance figures for the content published through GrowOS.

We use this data only to provide the GrowOS service to you. We do not use it for advertising targeting, we do not build profiles of the people who message you for any purpose beyond handling their message, and we do not sell it or transfer it to data brokers. You may withdraw our access at any time from your Facebook or Instagram settings, or by asking us to disconnect the account. When access is withdrawn we stop receiving new data from Meta and delete the stored access tokens.

1.4 Payment information

Payments for GrowOS subscriptions are processed by a third-party payment provider. Card details are entered on a page hosted by that provider. Sindal never receives, processes or stores your full card number, card expiry or security code. What we store is limited to: your billing contact details, the identifiers the payment provider assigns to your customer and subscription records, your plan, your subscription status and billing period, and, where the provider supplies it, the card brand and last four digits shown for your reference. Invoices and payment history are held by the payment provider and reached through a link from your account.

1.5 Technical data

Our servers record the usual technical information needed to operate and secure the service: IP address, browser and device type, pages or endpoints requested, time of request, and error diagnostics. We use this for security, abuse prevention, troubleshooting and capacity planning.

2. Why we use it

  • To provide GrowOS: producing your marketing content, publishing it to the accounts you connected, and handling comments and messages on your behalf.
  • To operate your account: authentication, organisation membership, support.
  • To take payment and manage your subscription, trial and renewals.
  • To keep the service secure: fraud and abuse prevention, audit records of commercially significant actions such as sign-ups, role changes and plan changes.
  • To comply with legal, accounting and tax obligations in Hong Kong.
  • To communicate with you about the service — service notices, billing notices and replies to your enquiries.

We do not sell personal data, and we do not use your business content or your customers' messages to advertise to anyone.

3. Automated content generation

GrowOS uses artificial intelligence to draft marketing content. To do this, the materials and directions you supply are sent to the AI service providers we use for text, image and video generation. These providers process the material to return a result to us. Generated content is presented to you for review; content is published to your connected accounts on your instruction and under the settings you have chosen. No automated decision is made about you that produces legal effects.

4. Who we share data with

Infrastructure and service providers
Hosting, storage, email delivery, error monitoring and the AI providers described above, each acting on our instructions and bound to protect the data.
Payment provider
Our third-party payment provider, for the purpose of taking payment and managing subscriptions. Card data is collected by them directly, not by us.
Meta Platforms
When GrowOS publishes content or replies on your behalf, that content is sent to Facebook or Instagram through Meta's official interfaces. Meta's own handling of that data is governed by Meta's terms and privacy policy.
Legal and professional
Where we are required to disclose by law, or where necessary to establish, exercise or defend legal claims, and to our auditors and professional advisers.

Some of these providers are located outside Hong Kong. Where personal data is transferred outside Hong Kong we take steps to ensure it remains protected to a comparable standard.

5. How long we keep it

We keep account, organisation and business content for as long as your account is active. After an account is closed we delete or anonymise the content within 90 days, except where we must keep records longer for accounting, tax or legal reasons — billing and transaction records are kept for seven years as required under Hong Kong law. Access tokens for connected Facebook and Instagram accounts are deleted as soon as the connection is removed. Security and audit logs are kept for up to 12 months.

6. How we protect it

Data is stored on servers under our control in Hong Kong. Access is restricted to the people who need it to operate the service. Traffic to our services is encrypted in transit. Passwords are stored only as cryptographic hashes. Databases are not exposed to the public internet. We keep encrypted backups and test our ability to restore them. No system is perfectly secure, but we treat customer and end-user data as confidential and design accordingly.

7. Your rights

Under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong you have the right to ask whether we hold personal data about you, to obtain a copy, and to request correction of data that is inaccurate. You may also ask us to delete data we no longer need to keep. To make a request, email [email protected] or write to us at the registered office above, identifying yourself and describing what you want. We will respond within 40 days as the Ordinance requires. We may need to verify your identity before acting on a request.

Requesting deletion of data obtained from Facebook or Instagram

To have data we obtained from your connected Facebook Page or Instagram account deleted, remove GrowOS's access from your Facebook or Instagram settings and email [email protected] stating the account concerned. On receipt we delete the stored tokens and associated platform data. Closing your GrowOS account has the same effect.

8. Children

GrowOS is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under 18.

9. Cookies

This website uses no cookies and no analytics or advertising trackers. Where you sign in to a Sindal account or to GrowOS, we set a session cookie that is strictly necessary to keep you signed in. It is not used for tracking or advertising.

10. Changes to this policy

If we change this policy we will update the effective date at the top of this page. Where a change materially affects how we handle your data we will also notify account holders directly.

11. Contact

Questions about this policy, or requests concerning your personal data, should be sent to [email protected], or in writing to Sindal Technology International Limited at the registered office shown at the top of this page.

中文版本

法律文件

私隱政策

星德科技國際有限公司(Sindal Technology International Limited)
生效日期:2026 年 8 月 29 日

本政策說明星德科技國際有限公司(下稱「星德」、「我們」)收集哪些個人資料、為何收集、與誰分享,以及你享有哪些權利。適用範圍包括本網站、GrowOS,以及任何用於訂閱 GrowOS 的星德客戶帳戶。

就本政策所述的個人資料而言,我們是資料使用者(data user)。註冊辦事處:

Sindal Technology International Limited
Flat/Rm D, Blk 6, 1/F, The Paramount
23 Shan Tong Road, Tai Po
New Territories, Hong Kong

私隱查詢及資料要求:[email protected]
一般查詢:[email protected]

1. 我們收集甚麼

1.1 帳戶與機構資料

當你建立星德客戶帳戶或 GrowOS 帳戶時,我們收集你的姓名、電郵地址、你設定的密碼(只以密碼雜湊形式儲存,不會保留可讀原文)、你選用的語言,以及你登記的商戶資料——商戶名稱、行業、聯絡途徑,以及你填寫的營業時間與地址。若你邀請同事加入,我們會儲存其電郵地址與在你機構內的角色。

1.2 你提供的內容

GrowOS 依你提供的素材運作:店舖、產品與作品的相片、商標、品牌資料,以及你就製作內容所給的書面指示。我們儲存這些素材、由此製作的行銷內容,以及該項工作的紀錄——草稿、修訂、確認,以及你與行銷助理之間的對話。

1.3 經你授權而取得的 Facebook 與 Instagram 資料

若你連接 Facebook 專頁或 Instagram 專業帳戶,我們只會在你完成 Meta 的授權流程並授出所要求的權限之後,才從 Meta 接收資料。其後我們接收並儲存的包括:

  • 你所連接的專頁與 Instagram 帳戶的識別碼、名稱與頭像,以及代你操作所需的存取權杖;
  • 經 GrowOS 發布到該等帳戶的貼文,連同其發布狀態與識別碼;
  • 該等帳戶收到的留言與私訊,包括發訊者在平台上的名稱、識別碼與訊息內容,以便 GrowOS 向你顯示並代你回覆;
  • 經 GrowOS 發布的內容的基本成效數字。

我們只將這些資料用於向你提供 GrowOS 服務。我們不會用於廣告定向;除處理訊息本身所需外,不會為向你發訊的人建立任何側寫;亦不會出售或轉移予資料經紀。你可隨時在 Facebook 或 Instagram 的設定中撤回我們的存取權,或要求我們解除連接。存取權一經撤回,我們即停止從 Meta 接收新資料,並刪除已儲存的存取權杖。

1.4 付款資料

GrowOS 訂閱的付款由第三方付款服務商處理,卡片資料在該服務商代管的頁面上輸入。星德永不接收、處理或儲存你的完整卡號、有效期或安全碼。我們儲存的僅限於:你的帳單聯絡資料、付款服務商為你的客戶與訂閱紀錄所編配的識別碼、你的方案、訂閱狀態與帳單週期,以及在服務商提供的情況下,供你辨識用的卡別與末四位數字。發票與付款紀錄由付款服務商保存,經你帳戶內的連結前往查閱。

1.5 技術資料

我們的伺服器記錄營運與保安所需的一般技術資料:IP 位址、瀏覽器與裝置類型、所請求的頁面或端點、請求時間,以及錯誤診斷資料。用途為保安、防止濫用、故障排查與容量規劃。

2. 用途

  • 提供 GrowOS:製作你的行銷內容、發布到你連接的帳戶、代你處理留言與訊息。
  • 營運你的帳戶:身分驗證、機構成員管理、客戶支援。
  • 收取款項並管理你的訂閱、試用與續期。
  • 維持服務保安:防止欺詐與濫用,並就註冊、角色變更、方案變更等具商業意義的動作保留審計紀錄。
  • 遵守香港的法律、會計與稅務責任。
  • 就服務與你聯絡——服務通知、帳單通知,以及回覆你的查詢。

我們不出售個人資料,亦不會利用你的商戶內容或你顧客的訊息向任何人投放廣告。

3. 自動生成內容

GrowOS 以人工智能草擬行銷內容。為此,你提供的素材與指示會傳送至我們用於文字、圖像與影片生成的 AI 服務商。該等服務商處理素材並把結果回傳給我們。生成的內容會交由你檢視;內容只在你的指示與你所選設定之下,才發布到你連接的帳戶。我們不會對你作出任何產生法律效果的自動化決定。

4. 我們與誰分享

基礎設施與服務供應商
主機託管、儲存、電郵發送、錯誤監察,以及上述 AI 服務商。各方均按我們的指示行事,並負有保護資料的責任。
付款服務商
第三方付款服務商,用途為收取款項及管理訂閱。卡片資料由其直接收集,不經我們。
Meta 平台
當 GrowOS 代你發布內容或回覆時,該等內容會透過 Meta 的官方介面傳送至 Facebook 或 Instagram。Meta 對該等資料的處理受 Meta 自身的條款與私隱政策規管。
法律與專業人士
在法律要求披露時,或為確立、行使或抗辯法律申索所必需時,以及向我們的核數師與專業顧問披露。

部分供應商位於香港以外。個人資料在轉移至香港以外時,我們會採取措施確保其仍受相當程度的保護。

5. 保留多久

帳戶、機構與商戶內容在你的帳戶有效期間一直保留。帳戶關閉後,我們於 90 日內刪除或匿名化相關內容;但基於會計、稅務或法律理由須較長保存者除外——帳單與交易紀錄依香港法例規定保存七年。已連接的 Facebook 與 Instagram 帳戶的存取權杖,在連接解除後即時刪除。保安與審計日誌最長保存 12 個月。

6. 我們如何保護

資料儲存於我們在香港自行控制的伺服器。存取權僅限於營運服務所必需的人員。往來我們服務的流量在傳輸過程中加密。密碼只以密碼雜湊形式儲存。資料庫不對公共互聯網開放。我們保存加密備份並測試還原能力。沒有系統是絕對安全的,但我們把客戶及其終端用戶的資料視為機密,並據此設計。

7. 你的權利

根據香港《個人資料(私隱)條例》(第 486 章),你有權查詢我們是否持有關於你的個人資料、索取副本,並要求更正不準確的資料。你亦可要求我們刪除已無須保留的資料。提出要求請電郵 [email protected],或以書面寄至上述註冊辦事處,說明你的身分與要求內容。我們會按條例規定於 40 日內回覆。在處理要求前,我們可能需要核實你的身分。

要求刪除來自 Facebook 或 Instagram 的資料

如要刪除我們從你所連接的 Facebook 專頁或 Instagram 帳戶取得的資料,請在 Facebook 或 Instagram 設定中移除 GrowOS 的存取權,並電郵 [email protected] 註明相關帳戶。我們收到後會刪除已儲存的權杖及相關平台資料。關閉 GrowOS 帳戶亦有相同效果。

8. 兒童

GrowOS 是商業工具,並非以兒童為對象。我們不會在知情下收集未滿 18 歲人士的個人資料。

9. Cookie

本網站不使用任何 cookie,亦沒有分析或廣告追蹤工具。當你登入星德帳戶或 GrowOS 時,我們會設定一個維持登入狀態所必需的 session cookie。該 cookie 不用於追蹤或廣告。

10. 政策修訂

如本政策有所修訂,我們會更新本頁頂部的生效日期。若修訂實質影響我們處理你資料的方式,我們會另行直接通知帳戶持有人。

11. 聯絡

就本政策的疑問,或有關你個人資料的要求,請電郵 [email protected],或以書面寄至本頁頂部所列星德科技國際有限公司的註冊辦事處。