LABs21 Innovation LABs21 Innovation
About
Services
Consultancy Design the path before codeFDE Embedded senior engineers who shipTraining Teach your team to own it
Knowledge
Product
Open Source Tools we ship in the openClosed Source Products in private beta
Pricing
Start a project
Legal

Privacy Policy

Effective date: 6 August 2026 · Last updated: 6 August 2026

LABs21 Innovation Limited ("we", "us", "the Company", or "LABs21") respects and protects the privacy of your personal data. This Privacy Policy explains how we collect, use, store, disclose, and safeguard the personal data you provide when you use our consultancy services, Software-as-a-Service (SaaS) platform, website (labs21.dev), and related offerings (collectively, the "Services").

This policy applies to all users of the Services. If you do not agree with this policy, please do not use the Services.

1. Introduction

This policy explains our data practices — what personal data we collect, why, how we store it, who we share it with, and your rights over your data. We handle your data in accordance with applicable law, including Hong Kong's Personal Data (Privacy) Ordinance (PDPO) and international frameworks such as the GDPR and CCPA.

2. Personal data we collect

We may collect the following categories of data:

2.1 Data you provide directly

  • Account data: name, email address, username, password (hashed), company name, job title
  • Billing and payment data: billing address, payment method details (card data is typically handled by a third-party payment processor; we do not store full card numbers)
  • Communications data: support enquiries, support requests, feedback
  • Project data: data you voluntarily provide for delivery purposes during Consultancy and Forward Deployed Engineering engagements

2.2 Data collected automatically

  • Usage data: login times, feature usage, click behaviour, session records
  • Device and technical data: IP address, browser type and version, operating system, device identifiers, referrer URL
  • Cookie and similar technologies data (see Section 10)

2.3 Data from third parties

Data provided by payment processors, analytics services, identity verification services, or other integrated services. Where applicable, we may process data that customers (acting as data controllers) upload to the Services, in which case we generally act as a data processor.

3. How we collect data

  • When you register an account, subscribe, fill in a form, or communicate with us
  • Automatically through cookies, log files, analytics tools, and during your use of the Services
  • From third-party service providers (e.g. payment gateways, analytics tools)

4. Purposes of data use

We use your personal data for the following purposes:

  • Providing, operating, maintaining, and improving the Services
  • Creating and managing your account
  • Processing subscriptions, payments, and billing
  • Responding to support requests and providing customer service
  • Sending service-related notifications (e.g. updates, security alerts)
  • Analyzing usage to improve the product and user experience
  • Marketing communications (only with your consent or where permitted by law; you may opt out at any time)
  • Detecting and preventing fraud and ensuring security
  • Complying with legal obligations
  • Other uses you have consented to

5. Legal basis for processing

  • Performance of a contract with you (providing the Services)
  • Legitimate interests (improving the Services, security, analytics)
  • Your consent (e.g. marketing)
  • Legal obligations

Under the Hong Kong PDPO, we ensure that collection purposes are lawful, directly related, and proportionate.

6. Data sharing and disclosure

We do not sell your personal data. We may share data in the following circumstances:

  • Service providers / sub-processors: hosting, payment processing, analytics, email services, customer support tools, etc. (only as needed to deliver the Services, and under contract)
  • Legal requirements: in response to court orders, government agencies, or legal process
  • Business transfers: mergers, acquisitions, or asset sales (we will make reasonable efforts to notify you)
  • With your consent, or as otherwise permitted by law

We maintain a list of sub-processors (available on request) and require them to take appropriate data protection measures.

7. Data retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or longer where required by law. Account data is typically retained for a reasonable period after account termination to handle follow-up matters, then deleted or anonymized. Usage logs may be retained for a shorter period.

8. Data security

We take reasonable technical and organizational measures to protect personal data, including encryption in transit, access controls, and regular security assessments. However, no internet transmission can be guaranteed fully secure. In the event of a data breach, we will notify the relevant authorities and affected individuals as required by applicable law.

9. Your rights

Depending on your location and applicable law, you may have the following rights:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete data (in certain circumstances)
  • Restrict or object to processing
  • Data portability
  • Withdraw consent (without affecting lawfully processed data prior to withdrawal)
  • (CCPA, etc.) request knowledge of, deletion of, or opt-out of "sale" or "sharing"

Hong Kong PDPO: You have the right to request access to and correction of personal data. We will handle reasonable requests within the statutory period (typically 40 days). To exercise your rights, contact us (see Section 14). We may need to verify your identity.

10. Cookies and tracking technologies

We use cookies and similar technologies to:

  • Provide essential functionality (login, security)
  • Analyze and improve the Services
  • Remember preferences

You can manage cookies through your browser settings. Some features may be affected if cookies are disabled.

11. Cross-border data transfers

Your data may be transferred to and stored in locations outside Hong Kong for processing. We take reasonable measures (including contractual terms) to ensure recipients provide a level of protection comparable to the PDPO.

12. Children's privacy

The Services are not directed at children under 18 (or the age of majority in their jurisdiction). We do not knowingly collect children's personal data. If we become aware of such data, we will delete it as soon as possible.

13. Changes to this policy

We may update this policy from time to time. For material changes, we will publish the updated version on our website and, where appropriate, notify you by email or other means. Continued use of the Services constitutes acceptance of the updated policy.

14. Contact us

For any questions, complaints, or rights requests regarding this Privacy Policy or your personal data, contact:

  • Email: [email protected]
  • Company: LABs21 Innovation Limited

We will make reasonable efforts to respond promptly.

This Privacy Policy is provided for reference only and does not constitute legal advice. For legal advice, consult a qualified lawyer.

LABs21 Innovation LABs21 Innovation

A consultancy and delivery practice for agent transformation. We design the path, then embed engineers to ship it.

Practice

  • Services
  • Consultancy
  • FDE
  • Training
  • GEO Audit

Products

  • agents-stack
  • Terminal
  • ARC

Connect

  • [email protected]
  • Start a project
  • Writing
© 2026 LABs21 Innovation Limited Privacy Policy · Terms of Service Consultancy + Delivery